Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.4%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists,…
ModificadaAlta (7.5)2.0%—Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+96/5/202011/8/2026
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over…
ModificadaCrítica (9.8)2.4%—Cisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x FirmwareCisco ASA 5515-x Firmware+96/5/202017/6/2026
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for…
ModificadaAlta (8.8)1.5%—Netgear Wc7500 FirmwareNetgear Wc7520 FirmwareNetgear Wc7600 Firmware22/4/202017/6/2026
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9.
ModificadaCrítica (9.8)2.6%—Netgear Wc7500 FirmwareNetgear Wc7520 FirmwareNetgear Wc7600v1 FirmwareNetgear Wc7600v2 Firmware+11/4/202017/6/2026
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2,…
ModificadaAlta (7.2)3.2%—Netgear Prosafe Wc9500 FirmwareNetgear Prosafe Wc7600 FirmwareNetgear Prosafe Wc7520 Firmware23/3/202017/6/2026
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.
ModificadaAlta (7.5)1.1%—Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+809/3/202016/6/2026
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
ModificadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+234/3/20207/10/2026
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI…
ModificadaMedia (5.3)0.35%—Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+17021/2/202017/6/2026
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring…
ModificadaAlta (7.5)0.86%—Cisco ASA 5500 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x FirmwareCisco ASA 5515-x Firmware+819/2/202016/6/2026
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of…
ModificadaMedia (6.1)0.67%—Cambiumnetworks Xh2-120 FirmwareCambiumnetworks Xr2436 FirmwareCambiumnetworks Xr520 FirmwareCambiumnetworks Xr620 Firmware17/2/202017/6/2026
An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.
ModificadaMedia (5.5)0.28%—Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M6500s FirmwareLenovo Thinkcentre M6500t FirmwareLenovo Thinkcentre M73p Firmware+17814/2/202017/6/2026
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
ModificadaMedia (5.5)0.56%—Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+42728/1/202017/6/2026
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.52%—Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+42328/1/202017/6/2026
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)1.4%💥 PoCCanonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+44117/1/202017/6/2026
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.3)0.34%—Intel Xeon Platinum 9282 FirmwareIntel Xeon Platinum 9242 FirmwareIntel Xeon Platinum 9222 FirmwareIntel Xeon Platinum 9221 Firmware+37416/12/201917/6/2026
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.
ModificadaMedia (6.7)0.39%—Intel Xeon E-2276m FirmwareIntel Xeon E-2286m FirmwareIntel Core I5-9500 FirmwareIntel Core I5-9600 Firmware+44014/11/201917/6/2026
Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaAlta (8.2)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of…
ModificadaMedia (6.7)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local…
ModificadaAlta (8.6)2.0%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 Firmware+92/10/201911/8/2026
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The…
ModificadaMedia (6.8)0.36%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+2375/8/201917/6/2026
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.…
ModificadaAlta (7.4)1.9%—Intel Rapid Storage Technology EnterpriseLenovo Thinkstation P520 FirmwareLenovo Thinkstation P520c FirmwareLenovo Thinkstation P720 Firmware+113/6/201917/6/2026
Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (6.7)0.40%—Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+4417/5/201917/6/2026
Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
ModificadaMedia (6.7)0.43%—Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+8817/5/201917/6/2026
Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.