Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 11% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 16/10/2024 | 17/6/2026 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Crítica (9.8) | 0.67% | — | Hdfgroup Hdf5 | 9/10/2024 | 17/6/2026 | HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. | |
| Analizada | Media (5.3) | 0.57% | — | HP 9yf88a FirmwareHP 9yf89a FirmwareHP 9yf90a FirmwareHP 9yf91a Firmware+98 | 2/10/2024 | 17/6/2026 | Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs. | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (4.6) | 0.26% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 0.50% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target… | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 0.79% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.9) | 0.47% | — | F5 Nginx AgentF5 Nginx Instance Manager | 22/8/2024 | 17/6/2026 | NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. | |
| Modificada | Media (5.7) | 0.32% | — | F5 Nginx Open SourceF5 Nginx Plus | 14/8/2024 | 17/6/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in… | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.3) | 0.30% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.1) | 0.15% | — | F5 Big-ip Next Central Manager | 14/8/2024 | 17/6/2026 | When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 14/8/2024 | 17/6/2026 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.9) | 0.44% | — | F5 Big-ip Next Central Manager | 14/8/2024 | 17/6/2026 | The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (8.7) | 0.63% | — | F5 Nginx Plus | 14/8/2024 | 17/6/2026 | When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.3) | 0.45% | — | F5 Big-ip Next Central Manager | 14/8/2024 | 17/6/2026 | BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (6.4) | 0.12% | — | AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+101 | 13/8/2024 | 17/6/2026 | A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution. | |
| Modificada | Alta (8.2) | 0.16% | — | AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+65 | 13/8/2024 | 17/6/2026 | An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution. | |
| Analizada | Media (5.3) | 0.93% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. | |
| Analizada | Media (5.3) | 0.87% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory. | |
| Analizada | Media (6.5) | 0.86% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. | |
| Analizada | Media (4.8) | 0.89% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility… | |
| Aplazada | Crítica (9.9) | 0.37% | — | Anpviz Ipc-d250AIAnpviz Ipc-d260AIAnpviz Ipc-b850AIAnpviz Ipc-d850AI+14 | 28/5/2024 | 17/6/2026 | Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and… |