Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.18% | — | Intel Ethernet 800 Series Controllers Driver | 14/8/2024 | 17/6/2026 | Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7) | 0.53% | — | Intel Ethernet 800 Series Controllers Driver | 14/8/2024 | 17/6/2026 | Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Analizada | Crítica (9.3) | 0.18% | — | Intel Ethernet 800 Series Controllers Driver | 14/8/2024 | 17/6/2026 | Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.8) | 0.55% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 13/8/2024 | 17/6/2026 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A… | |
| Aplazada | Media (6.5) | 0.44% | — | Bas-ip AV Series FirmwareAIBas-ip AA Series FirmwareAIBas-ip BA Series FirmwareAIBas-ip CR Series FirmwareAI | 3/7/2024 | 17/6/2026 | BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD before firmware v3.9.2 allows… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Aplazada | Media (5.3) | 0.46% | — | Ipcom EX2 SeriesAIIpcom VE2 SeriesAI | 12/6/2024 | 17/6/2026 | Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet. | |
| Aplazada | Baja (3.3) | 0.15% | — | Yubico Yubikey 5 SeriesAIYubico Security KEY SeriesAIYubico Yubikey BIO SeriesAIYubico Yubikey 5 FipsAI | 29/5/2024 | 17/6/2026 | Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control. | |
| Aplazada | Media (6) | 0.22% | — | Intel Data Center GPU MAX Series 1100AIIntel Data Center GPU MAX Series 1550AI | 16/5/2024 | 17/6/2026 | Improper conditions check in the Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow an privileged user to potentially enable denial of service via local access. | |
| Analizada | Alta (7.5) | 0.52% | — | IBM Txseries FOR Multiplatform | 14/5/2024 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192. | |
| Modificada | Media (6.1) | 0.49% | — | IBM Txseries FOR Multiplatform | 14/5/2024 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 280191. | |
| Analizada | Baja (3.3) | 0.22% | — | IBM Txseries FOR Multiplatform | 14/5/2024 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190. | |
| Aplazada | Alta (8.1) | 0.78% | — | Silabs 500 Series SDKAI | 7/5/2024 | 17/6/2026 | A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all versions of Silicon Labs 500 Series SDK prior to v6.85.2 running on Silicon Labs 500 series Z-wave devices. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A successful exploit could allow an attacker… | |
| Aplazada | Media (6.2) | 0.44% | — | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter sanitization. A… | |
| Aplazada | Media (4.2) | 0.24% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct a path traversal attack due to insufficient input validation. A successful… | |
| Aplazada | Alta (7.5) | 0.62% | 💥 PoC | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an… | |
| Aplazada | Media (6.4) | 0.25% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker to conduct a buffer overflow attack due to insufficient bounds checking and input sanitization. A successful exploit… | |
| Analizada | Alta (7.8) | 0.17% | — | Beyondtrust U-series Appliance | 19/4/2024 | 17/6/2026 | Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3. | |
| Analizada | Alta (7.8) | 0.17% | — | Beyondtrust U-series Appliance | 19/4/2024 | 17/6/2026 | Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3. | |
| Analizada | Media (5.5) | 0.27% | — | Linux KernelDebian LinuxNetapp 8300 FirmwareNetapp 8700 Firmware+6 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must be registered before registering the generic netlink family. | |
| Analizada | Media (5.5) | 0.26% | — | Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+25 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mitsubishielectric Melsec-q SeriesAIMitsubishielectric Melsec-l SeriesAI | 15/3/2024 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mitsubishielectric Melsec-q SeriesAIMitsubishielectric Melsec-l SeriesAI | 15/3/2024 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Mitsubishielectric Melsec-q SeriesAIMitsubishielectric Melsec-l SeriesAI | 15/3/2024 | 17/6/2026 | Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet. |