Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

872 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitZyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+1525/4/202317/6/2026
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS…
ModificadaAlta (8.8)1.5%—Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+1524/4/202317/6/2026
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions…
ModificadaMedia (4.8)0.34%—Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+1524/4/202317/6/2026
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which…
ModificadaMedia (6.5)0.77%—Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+4724/4/202317/6/2026
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions…
ModificadaAlta (7.5)0.88%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+1424/4/202317/6/2026
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00…
ModificadaAlta (8.1)0.69%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+1424/4/202317/6/2026
The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly…
ModificadaAlta (7.5)1.1%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+824/4/202317/6/2026
A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote…
ModificadaAlta (7.2)1.0%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+724/4/202317/6/2026
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp”…
ModificadaAlta (8.1)1.3%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+724/4/202317/6/2026
A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in…
ModificadaAlta (7.8)0.28%—Flexera Revenera Installshield29/3/202317/6/2026
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
ModificadaAlta (7.5)0.65%—Flexera Flexnet Publisher29/3/202317/6/2026
A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.
ModificadaAlta (7.8)0.17%—Flexera Flexnet ManagerFlexera Flexnet Manager Suite 201529/3/202317/6/2026
A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.
ModificadaAlta (7.8)0.22%—Softmaker Flexipdf23/3/202317/6/2026
A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.
ModificadaMedia (6.1)0.33%—HPE Flexfabric 5700 40xg 2qsfp+ FirmwareHPE Flexfabric 5700 48G 4XG 2qsfp+ Firmware22/3/202317/6/2026
Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61…
ModificadaMedia (5.5)0.19%—HPE Superdome Flex 280 Server FirmwareHPE Superdome Flex Server Firmware10/3/202317/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locally exploited to allow disclosure of information. HPE has made the following software to resolve the vulnerability in HPE Superdome Flex Servers v3.65.8 and Superdome Flex 280…
ModificadaMedia (5.4)0.54%—Mekshq Meks Flexible Shortcodes13/2/202317/6/2026
The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaAlta (7.2)2.8%—Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+217/2/202317/6/2026
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an…
ModificadaMedia (5.4)0.61%—Flexible Captcha Project Flexible Captcha6/2/202317/6/2026
The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7)0.14%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3131/2/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
ModificadaAlta (7.8)0.31%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3231/2/202317/6/2026
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.17%—HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+3731/2/202317/6/2026
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.34%—Lenovo 100e 2ND GEN FirmwareLenovo 100w GEN 3 FirmwareLenovo 13W Yoga FirmwareLenovo 14W GEN 2 Firmware+6626/1/202317/6/2026
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
ModificadaAlta (7.8)0.27%—HPE Superdome Flex 280 FirmwareHPE Superdome Flex Firmware5/1/202317/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome Flex firmware 3.60.50 and below and…