Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Out-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Unchecked return value in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow a priviledged user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 3.1% | — | Opnsense | 9/8/2023 | 17/6/2026 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands. | |
| Modificada | Crítica (9.6) | 2.6% | 💥 Exploit | Opnsense | 9/8/2023 | 17/6/2026 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php. | |
| Modificada | Media (5.4) | 0.48% | — | Opnsense | 9/8/2023 | 17/6/2026 | The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization. | |
| Modificada | Alta (7.5) | 0.72% | — | Opnsense | 9/8/2023 | 17/6/2026 | Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. | |
| Modificada | Crítica (9.8) | 0.99% | — | Opnsense | 9/8/2023 | 9/7/2026 | Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation. | |
| Modificada | Alta (7.5) | 0.79% | — | Opnsense | 9/8/2023 | 9/7/2026 | OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Opnsense | 9/8/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Crítica (9.8) | 3.6% | — | Opnsense | 9/8/2023 | 17/6/2026 | A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file. | |
| Modificada | Media (6.1) | 0.57% | — | Opnsense | 9/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path. | |
| Modificada | Media (6.5) | 0.40% | — | Opnsense | 9/8/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Media (6.1) | 0.59% | — | Opnsense | 9/8/2023 | 17/6/2026 | An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL. | |
| Modificada | Alta (7.2) | 1.4% | — | Opnsense | 9/8/2023 | 17/6/2026 | A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive. | |
| Modificada | Media (6.5) | 0.55% | — | Anasystem Sensmini M4 Firmware | 30/7/2023 | 17/6/2026 | AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device | |
| Modificada | Media (5.3) | 0.54% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C… | |
| Modificada | Media (5.3) | 0.57% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan.… | |
| Modificada | Alta (7.5) | 0.61% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Alta (7.8) | 0.21% | — | Digitalpersona Fpsensor Project Digitalpersona Fpsensor | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773… |