Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+9 | 6/5/2020 | 11/8/2026 | A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists,… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+9 | 6/5/2020 | 11/8/2026 | A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over… | |
| Modificada | Crítica (9.8) | 2.4% | — | Cisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x FirmwareCisco ASA 5515-x Firmware+9 | 6/5/2020 | 17/6/2026 | A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for… | |
| Modificada | Alta (8.8) | 1.5% | — | Netgear Wc7500 FirmwareNetgear Wc7520 FirmwareNetgear Wc7600 Firmware | 22/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9. | |
| Modificada | Crítica (9.8) | 2.6% | — | Netgear Wc7500 FirmwareNetgear Wc7520 FirmwareNetgear Wc7600v1 FirmwareNetgear Wc7600v2 Firmware+1 | 1/4/2020 | 17/6/2026 | NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2,… | |
| Modificada | Alta (7.2) | 3.2% | — | Netgear Prosafe Wc9500 FirmwareNetgear Prosafe Wc7600 FirmwareNetgear Prosafe Wc7520 Firmware | 23/3/2020 | 17/6/2026 | NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+80 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. | |
| Modificada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+23 | 4/3/2020 | 7/10/2026 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI… | |
| Modificada | Media (5.3) | 0.35% | — | Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+170 | 21/2/2020 | 17/6/2026 | Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring… | |
| Modificada | Alta (7.5) | 0.86% | — | Cisco ASA 5500 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x FirmwareCisco ASA 5515-x Firmware+8 | 19/2/2020 | 16/6/2026 | A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of… | |
| Modificada | Media (6.1) | 0.67% | — | Cambiumnetworks Xh2-120 FirmwareCambiumnetworks Xr2436 FirmwareCambiumnetworks Xr520 FirmwareCambiumnetworks Xr620 Firmware | 17/2/2020 | 17/6/2026 | An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS. | |
| Modificada | Media (5.5) | 0.28% | — | Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M6500s FirmwareLenovo Thinkcentre M6500t FirmwareLenovo Thinkcentre M73p Firmware+178 | 14/2/2020 | 17/6/2026 | Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled. | |
| Modificada | Media (5.5) | 0.56% | — | Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+427 | 28/1/2020 | 17/6/2026 | Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.52% | — | Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+423 | 28/1/2020 | 17/6/2026 | Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 1.4% | 💥 PoC | Canonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+441 | 17/1/2020 | 17/6/2026 | Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.3) | 0.34% | — | Intel Xeon Platinum 9282 FirmwareIntel Xeon Platinum 9242 FirmwareIntel Xeon Platinum 9222 FirmwareIntel Xeon Platinum 9221 Firmware+374 | 16/12/2019 | 17/6/2026 | Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access. | |
| Modificada | Media (6.7) | 0.39% | — | Intel Xeon E-2276m FirmwareIntel Xeon E-2286m FirmwareIntel Core I5-9500 FirmwareIntel Core I5-9600 Firmware+440 | 14/11/2019 | 17/6/2026 | Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Alta (8.2) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local… | |
| Modificada | Alta (8.6) | 2.0% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 Firmware+9 | 2/10/2019 | 11/8/2026 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The… | |
| Modificada | Media (6.8) | 0.36% | — | Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+237 | 5/8/2019 | 17/6/2026 | Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.… | |
| Modificada | Alta (7.4) | 1.9% | — | Intel Rapid Storage Technology EnterpriseLenovo Thinkstation P520 FirmwareLenovo Thinkstation P520c FirmwareLenovo Thinkstation P720 Firmware+1 | 13/6/2019 | 17/6/2026 | Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (6.7) | 0.40% | — | Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+44 | 17/5/2019 | 17/6/2026 | Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.43% | — | Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+88 | 17/5/2019 | 17/6/2026 | Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. |