Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.69% | 💥 Exploit | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command. | |
| Modificada | Media (4.6) | 0.40% | — | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts. | |
| Modificada | Baja (2.1) | 0.32% | — | Info Touch Surfnet KioskAI | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI. | |
| Modificada | Alta (7.2) | 0.43% | — | Mandrakesoft Mandrake Multi Network FirewallSpeedtouch USB DriverGentoo LinuxMandrakesoft Mandrake Linux+1 | 23/12/2004 | 16/6/2026 | Vulnerabilidad de cadena de formato en Speedtouch USB driver anteriores a 1.3.1 permite a usuarios locales ejecutar código de su elección mediante modem_run pppoa2, o pppoa3 | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Thomson Speedtouch | 5/8/2004 | 16/6/2026 | Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | |
| Modificada | Media (4.6) | 0.37% | — | Logitech Cordless Freedom Itouch KeyboardLogitech Cordless Itouch KeyboardLogitech Itouch Keyboard | 31/12/2002 | 16/6/2026 | Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button. | |
| Modificada | Media (5) | 1.9% | — | Alcatel Speed Touch Home | 25/3/2002 | 16/6/2026 | el modem de Alcatel Speed Touch Home ADSL permite e atacantes remotos causar una negación de servicio (reboot) via a scaneo de la red con paquetes anormales, como nmap con detección de OS | |
| Modificada | Alta (7.5) | 2.4% | — | Alcatel Adsl Modem 1000Alcatel Speed Touch Adsl Modem | 31/12/2001 | 16/6/2026 | Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication. | |
| Modificada | Alta (7.5) | 1.7% | — | Logitech Cordless FreedomLogitech Cordless Freedom NavigatorLogitech Cordless Freedom PROLogitech Cordless Itouch Keyboard | 18/10/2001 | 16/6/2026 | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 3.7% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. | |
| Modificada | Alta (7.5) | 3.5% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 2.0% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations. |