Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.44% | — | Qualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Mdm9205 Firmware+26 | 12/2/2023 | 17/6/2026 | Memory corruption in modem due to improper length check while copying into memory | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Mdm8207 Firmware+30 | 12/2/2023 | 17/6/2026 | Information disclosure in modem due to buffer over-read while processing response from DNS server | |
| Modificada | Alta (7.2) | 2.8% | — | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+21 | 7/2/2023 | 17/6/2026 | A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Domain Name SystemF5 Big-ip Local Traffic ManagerF5 Big-ip 10000s FirmwareF5 Big-ip 10200v Firmware+30 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic… | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Ideacentre 510-15ikl FirmwareLenovo Ideacentre 510s-08ikl FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 310-15asr Firmware+132 | 26/12/2022 | 17/6/2026 | Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. | |
| Modificada | Media (6.5) | 0.32% | — | Sick Rfu630-04100 FirmwareSick Rfu630-04100s01 FirmwareSick Rfu630-04101 FirmwareSick Rfu630-04102 Firmware+20 | 13/12/2022 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is… | |
| Modificada | Alta (7.5) | 0.61% | — | Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 FirmwareSchneider-electric Modicon M340 Bmxp3420102 Firmware+10 | 22/11/2022 | 17/6/2026 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100… | |
| Modificada | Alta (8.2) | 0.69% | — | Moxa Nport 5110 Firmware | 31/8/2022 | 17/6/2026 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite values in memory, causing a denial-of-service condition or potentially bricking the device. | |
| Modificada | Alta (7.5) | 0.81% | — | Moxa Nport 5110 Firmware | 31/8/2022 | 17/6/2026 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive. | |
| Modificada | Crítica (9.8) | 0.79% | — | Seiko-sol Skybridge Mb-a100 FirmwareSeiko-sol Skybridge Mb-a110 Firmware | 29/8/2022 | 17/6/2026 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg. | |
| Modificada | Crítica (9.8) | 1.1% | — | Seiko-sol Skybridge Mb-a100 FirmwareSeiko-sol Skybridge Mb-a110 Firmware | 29/8/2022 | 17/6/2026 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file. | |
| Modificada | Crítica (9.8) | 1.6% | — | Seiko-sol Skybridge Mb-a100 FirmwareSeiko-sol Skybridge Mb-a110 Firmware | 29/8/2022 | 17/6/2026 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01. | |
| Modificada | Media (6.7) | 0.34% | — | Cisco Firepower 4110 FirmwareCisco Firepower 4112 FirmwareCisco Firepower 4115 FirmwareCisco Firepower 4120 Firmware+8 | 25/8/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The attacker would need to have Administrator privileges on the device. This vulnerability is due to insufficient input validation of commands supplied by… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+21 | 19/7/2022 | 17/6/2026 | A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions… | |
| Modificada | Media (6.5) | 1.4% | — | Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+21 | 19/7/2022 | 17/6/2026 | A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX… | |
| Modificada | Alta (7.8) | 4.8% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00… | |
| Modificada | Alta (7.8) | 6.2% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions… | |
| Modificada | Media (6.5) | 0.71% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+28 | 24/5/2022 | 17/6/2026 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through… | |
| Modificada | Media (6.1) | 9.4% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+28 | 24/5/2022 | 17/6/2026 | A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to… | |
| Modificada | Media (5.5) | 0.27% | — | Intel Core I9-7940x FirmwareIntel Core I9-7960x FirmwareIntel Core I9-7980xe FirmwareIntel Core I9-7920x Firmware+142 | 12/5/2022 | 17/6/2026 | Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.30% | — | Intel Core I9-7940x FirmwareIntel Core I9-7960x FirmwareIntel Core I9-7980xe FirmwareIntel Core I9-7920x Firmware+142 | 12/5/2022 | 17/6/2026 | Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Baja (2.7) | 0.66% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+10 | 13/4/2022 | 17/6/2026 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | |
| Modificada | Media (6.1) | 0.53% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+8 | 13/4/2022 | 17/6/2026 | Reflected cross site scripting (XSS) | |
| Modificada | Crítica (9.8) | 95% | 💥 Exploit | Zyxel Usg40 FirmwareZyxel Usg40w FirmwareZyxel Usg60 FirmwareZyxel Usg60w Firmware+19 | 28/3/2022 | 17/6/2026 | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through… | |
| Modificada | Media (4.9) | 0.69% | — | Fujifilm Apeosport-iv 7080 FirmwareFujifilm Apeosport-iv 6080 FirmwareFujifilm Apeosport-iv 5080 FirmwareFujifilm Apeosport-iv 3065 Firmware+156 | 3/3/2022 | 17/6/2026 | A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on… |