Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—Dlink Dir-882 A1 Firmware7/4/202317/6/2026
D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaMedia (4.4)0.19%—Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+1116/2/202317/6/2026
Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)41%—Dlink Dir-859 A1 Firmware19/1/202317/6/2026
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
ModificadaAlta (7.2)1.5%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan3Settings module.
ModificadaAlta (7.2)1.8%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key parameter in the SetWLanRadioSecurity module.
ModificadaAlta (7.2)1.4%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.
ModificadaAlta (7.2)1.4%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module.
ModificadaAlta (7.2)1.4%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetDynamicDNSSettings module.
ModificadaAlta (7.2)1.4%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK parameter in the SetQuickVPNSettings module.
ModificadaAlta (7.2)1.5%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWanSettings module.
ModificadaAlta (7.2)1.5%—Dlink Dir-882 A1 Firmware23/12/202217/6/2026
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan2Settings module.
ModificadaCrítica (9.8)1.5%—HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+269612/12/202217/6/2026
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
ModificadaMedia (6.1)0.90%—Mitsubishielectric Mac-587if-e FirmwareMitsubishielectric Mac-587if2-e FirmwareMitsubishielectric Mac-507if-e FirmwareMitsubishielectric Mac-588if-e Firmware+1158/11/202217/6/2026
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and…
ModificadaCrítica (9.8)0.97%—Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+1748/11/202217/6/2026
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy…
ModificadaAlta (8.8)1.6%—Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware8/11/202217/6/2026
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All versions < V3.10), SICAM P850 (All…
ModificadaAlta (8.8)1.5%—Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware8/11/202217/6/2026
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All versions < V3.10), SICAM P850 (All…
ModificadaAlta (8.8)1.6%—Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware8/11/202217/6/2026
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions < V2.50), SICAM…
ModificadaAlta (8.8)0.52%—Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware8/11/202217/6/2026
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie after login/logout and also accept user…
ModificadaAlta (8.8)0.94%—Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+18211/10/202217/6/2026
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.
ModificadaAlta (8)0.78%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
ModificadaMedia (5.3)0.60%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
ModificadaAlta (7.8)0.24%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
ModificadaMedia (6.8)0.23%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
ModificadaMedia (5.3)0.75%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
ModificadaCrítica (9.8)1.3%—Dahuasecurity Ipc-hx1xxx FirmwareDahuasecurity Ipc-hx2xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5(4)(3)xxx Firmware+2413/1/202217/6/2026
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.