Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Out-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.4)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Unchecked return value in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow a priviledged user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)3.1%—Opnsense9/8/202317/6/2026
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.
ModificadaCrítica (9.6)2.6%💥 ExploitOpnsense9/8/202317/6/2026
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
ModificadaMedia (5.4)0.48%—Opnsense9/8/202317/6/2026
The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
ModificadaAlta (7.5)0.72%—Opnsense9/8/202317/6/2026
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
ModificadaCrítica (9.8)0.99%—Opnsense9/8/20239/7/2026
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
ModificadaAlta (7.5)0.79%—Opnsense9/8/20239/7/2026
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
ModificadaMedia (6.1)1.2%💥 ExploitOpnsense9/8/202317/6/2026
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaCrítica (9.8)3.6%—Opnsense9/8/202317/6/2026
A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.
ModificadaMedia (6.1)0.57%—Opnsense9/8/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.
ModificadaMedia (6.5)0.40%—Opnsense9/8/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
ModificadaMedia (6.1)0.59%—Opnsense9/8/202317/6/2026
An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
ModificadaAlta (7.2)1.4%—Opnsense9/8/202317/6/2026
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.
ModificadaMedia (6.5)0.55%—Anasystem Sensmini M4 Firmware30/7/202317/6/2026
AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device
ModificadaMedia (5.3)0.54%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C…
ModificadaMedia (5.3)0.57%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan.…
ModificadaAlta (7.5)0.61%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C…
ModificadaCrítica (9.8)1.1%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series…
ModificadaCrítica (9.8)1.1%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series…
ModificadaCrítica (9.8)1.2%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C…
ModificadaCrítica (9.8)1.2%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C…
ModificadaCrítica (9.8)1.1%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C…
ModificadaCrítica (9.8)1.1%—Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+4111/5/202317/6/2026
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series…
ModificadaAlta (7.8)0.21%—Digitalpersona Fpsensor Project Digitalpersona Fpsensor11/5/202317/6/2026
A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773…