Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 3.0% | — | Dell Powervault Ml6000 FirmwareDell Powervault Ml6000Quantum Scalar I500 FirmwareQuantum Scalar I500 | 2/6/2014 | 17/6/2026 | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter. | |
| Modificada | Alta (10) | 3.2% | — | Siemens Scalance X-200 Series FirmwareSiemens Scalance X-200Siemens Scalance X-200irt | 3/10/2013 | 16/6/2026 | The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface. | |
| Modificada | Alta (8.3) | 3.0% | — | Siemens Scalance X-200 Series FirmwareSiemens Scalance X-200Siemens Scalance X-200rnaSiemens Scalance X200-4p IRT+5 | 17/9/2013 | 16/6/2026 | The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value. | |
| Modificada | Alta (10) | 5.9% | — | Siemens Scalance W700 Series FirmwareSiemens Scalance W744-1Siemens Scalance W744-1proSiemens Scalance W746-1+13 | 1/8/2013 | 16/6/2026 | Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary code via a (1) SSH or (2) TELNET connection. | |
| Modificada | Media (6.6) | 0.95% | — | Siemens Scalance W700 Series FirmwareSiemens Scalance W744-1Siemens Scalance W744-1proSiemens Scalance W746-1+13 | 1/8/2013 | 16/6/2026 | Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship. | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Scalance X200irt FirmwareSiemens Scalance X200-4p IRTSiemens Scalance X201-3p IRTSiemens Scalance X202-2irt+3 | 24/5/2013 | 16/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The implementation of SNMPv3 does not check the user… | |
| Modificada | Alta (8) | 1.2% | — | Siemens Scalance X200irt FirmwareSiemens Scalance X200-4p IRTSiemens Scalance X201-3p IRTSiemens Scalance X202-2irt+3 | 24/5/2013 | 16/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced… | |
| Modificada | Alta (7.8) | 6.1% | — | Siemens Scalance X414-3e FirmwareSiemens Scalance X414-3eSiemens Scalance X308-2m FirmwareSiemens Scalance X308-2m+6 | 18/4/2012 | 16/6/2026 | Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a… | |
| Modificada | Media (6.1) | 1.6% | — | Siemens Scalance S FirmwareSiemens Scalance S602Siemens Scalance S612Siemens Scalance S613 | 18/4/2012 | 16/6/2026 | Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame. | |
| Modificada | Alta (10) | 5.0% | — | Siemens Scalance S FirmwareSiemens Scalance S602Siemens Scalance S612Siemens Scalance S613 | 18/4/2012 | 16/6/2026 | The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password. | |
| Modificada | Alta (7.5) | 3.5% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+5 | 22/3/2012 | 16/6/2026 | The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier… | |
| Modificada | Media (6) | 1.0% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests… | |
| Modificada | Baja (3.5) | 1.2% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Media (5) | 2.1% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter. | |
| Modificada | Media (5) | 1.4% | — | Open Group Scalable OGO | 30/11/2004 | 16/6/2026 | Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users. | |
| Modificada | Media (5) | 77% | 💥 Exploit | Openbsd OpensshOpenpkgSiemens Scalance X204rna ECC FirmwareSiemens Scalance X204rna Firmware | 12/5/2003 | 16/6/2026 | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. |