Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.3%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+2119/11/202117/6/2026
During installation with certain driver software or application packages an arbitrary code execution could occur.
ModificadaMedia (5.5)0.42%—Intel Core I7-8510y FirmwareIntel Core I7-8500y FirmwareIntel Core I5-8310y FirmwareIntel Core I5-8210y Firmware+29712/11/202017/6/2026
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.45%—Intel Core I7-8510y FirmwareIntel Core I7-8500y FirmwareIntel Core I5-8310y FirmwareIntel Core I5-8210y Firmware+29512/11/202017/6/2026
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)1.4%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
ModificadaMedia (6.5)1.2%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
ModificadaMedia (6.5)1.7%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.
ModificadaAlta (8.8)8.6%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
ModificadaMedia (6.1)0.74%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
ModificadaMedia (6.5)0.68%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
ModificadaAlta (8.8)0.99%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
ModificadaAlta (7.5)1.1%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
ModificadaAlta (7.5)2.0%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
ModificadaAlta (8.8)0.69%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
ModificadaMedia (5.4)0.64%—Teltonika-networks Gateway Trb245 Firmware17/7/202017/6/2026
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.
ModificadaMedia (5.5)0.56%—Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+42728/1/202017/6/2026
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.52%—Intel Core I7-8700b FirmwareIntel Core I7-8569u FirmwareIntel Core I7 8650u FirmwareIntel Core I7 8565u Firmware+42328/1/202017/6/2026
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)1.4%—Canonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+44117/1/202017/6/2026
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.3)0.34%—Intel Xeon Platinum 9282 FirmwareIntel Xeon Platinum 9242 FirmwareIntel Xeon Platinum 9222 FirmwareIntel Xeon Platinum 9221 Firmware+37416/12/201917/6/2026
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.
ModificadaMedia (6.7)0.68%—Intel Xeon E3-1585 FirmwareIntel Xeon E3-1585l FirmwareIntel Xeon E3-1578l FirmwareIntel Xeon E3-1575m Firmware+26016/12/201917/6/2026
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaMedia (6.5)3.1%—Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+15614/11/201917/6/2026
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
ModificadaBaja (3.3)0.39%—Intel I9-9900x FirmwareIntel I9-9920x FirmwareIntel I9-9960x FirmwareIntel I9-9980xe Firmware+18413/6/201917/6/2026
Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical address information disclosure via local access.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
ModificadaCrítica (9.8)80%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.