Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.17%—Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+40322/2/202117/6/2026
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaCrítica (9.8)0.83%—Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8030 Firmware+50122/2/202117/6/2026
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaMedia (6.7)0.33%—Intel Pentium J6425 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+5713/11/202017/6/2026
Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.42%—Intel Core I7-8510y FirmwareIntel Core I7-8500y FirmwareIntel Core I5-8310y FirmwareIntel Core I5-8210y Firmware+29712/11/202017/6/2026
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.45%—Intel Core I7-8510y FirmwareIntel Core I7-8500y FirmwareIntel Core I5-8310y FirmwareIntel Core I5-8210y Firmware+29512/11/202017/6/2026
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (8.8)0.97%—Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware6/8/202017/6/2026
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0,…
ModificadaAlta (8.8)1.2%—Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware6/8/202017/6/2026
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and…
ModificadaCrítica (9.8)1.6%—Dlink Dap-1520 Firmware22/7/202017/6/2026
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi binary. On the login page, the web interface restricts the password input field to a fixed length of 15 characters. The…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaMedia (6.7)0.34%—Lenovo 130-14ast FirmwareLenovo 130-14ikb FirmwareLenovo 130-15ast FirmwareLenovo 130-15ikb Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
ModificadaCrítica (9.8)2.6%—Infomark Iml500 FirmwareInfomark Iml520 Firmware7/5/202017/6/2026
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
ModificadaAlta (8.6)2.0%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The…
ModificadaAlta (7.5)1.9%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this…
ModificadaAlta (7.5)2.0%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+106/5/202011/8/2026
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…
ModificadaAlta (8.6)1.9%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+106/5/202011/8/2026
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of…
ModificadaAlta (7.5)1.9%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+106/5/202011/8/2026
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of…
ModificadaAlta (8.6)1.9%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+106/5/202011/8/2026
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to…
ModificadaAlta (8.6)1.9%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the…
ModificadaMedia (5.3)1.7%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The…
ModificadaCrítica (9.1)97%💥 ExploitCisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+106/5/202011/8/2026
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The…