Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1028 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.66%—Intel Compute Module Mfs2600ki Firmware15/4/202017/6/2026
Improper conditions check for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaAlta (8.8)0.64%—Intel Compute Module Mfs2600ki Firmware15/4/202017/6/2026
Insufficient control flow for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaMedia (6.5)0.47%—Intel Compute Module Mfs2600ki Firmware15/4/202017/6/2026
Buffer overflow in Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (5.4)0.70%—Prestashop Faceted Search Module25/3/202017/6/2026
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
ModificadaAlta (7.8)0.34%—Intel Optane DC Persistent Memory Module Management12/3/202017/6/2026
Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.
ModificadaMedia (5.9)6.0%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+1021/2/202016/6/2026
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string…
ModificadaAlta (7.5)0.76%—Huawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6500 Firmware+217/2/202017/6/2026
Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V500R005C00 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful exploit may lead to…
ModificadaAlta (7.5)1.0%—Cisco ACE Application Control Engine Module A27/2/202016/6/2026
Cisco ACE A2(3.6) allows log retention DoS.
ModificadaCrítica (9.8)2.9%—Module-metadata Project Module-metadataFedoraproject Fedora28/1/202016/6/2026
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
ModificadaMedia (5.3)2.5%—NTPF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+218/1/202017/6/2026
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
ModificadaAlta (7.5)0.97%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+223/1/202017/6/2026
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.
ModificadaCrítica (9.8)3.8%—Amazon Blink XT2 Sync Module Firmware31/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
ModificadaMedia (5.3)1.1%—Remise Payment Module26/12/201917/6/2026
REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_type] via unspecified vectors.
ModificadaMedia (6.1)0.78%—Remise Payment Module26/12/201917/6/2026
Cross-site scripting vulnerability in REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.3)1.6%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaMedia (6.1)0.89%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaAlta (7.5)1.9%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaCrítica (9.8)3.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.
ModificadaAlta (8.8)1.2%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.
ModificadaMedia (6.8)1.0%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
ModificadaAlta (7.5)2.3%—Module-signature Project Module-signatureCanonical Ubuntu Linux29/11/201917/6/2026
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
ModificadaCrítica (9.8)2.0%—Yubico PAM ModuleDebian Linux26/11/201916/6/2026
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question…
Orbitaley — Vulnerabilidades