Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-882 A1 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Media (4.4) | 0.19% | — | Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+11 | 16/2/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 41% | — | Dlink Dir-859 A1 Firmware | 19/1/2023 | 17/6/2026 | D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function. | |
| Modificada | Alta (7.2) | 1.5% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan3Settings module. | |
| Modificada | Alta (7.2) | 1.8% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key parameter in the SetWLanRadioSecurity module. | |
| Modificada | Alta (7.2) | 1.4% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module. | |
| Modificada | Alta (7.2) | 1.4% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module. | |
| Modificada | Alta (7.2) | 1.4% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetDynamicDNSSettings module. | |
| Modificada | Alta (7.2) | 1.4% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK parameter in the SetQuickVPNSettings module. | |
| Modificada | Alta (7.2) | 1.5% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWanSettings module. | |
| Modificada | Alta (7.2) | 1.5% | — | Dlink Dir-882 A1 Firmware | 23/12/2022 | 17/6/2026 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan2Settings module. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Media (6.1) | 0.90% | — | Mitsubishielectric Mac-587if-e FirmwareMitsubishielectric Mac-587if2-e FirmwareMitsubishielectric Mac-507if-e FirmwareMitsubishielectric Mac-588if-e Firmware+115 | 8/11/2022 | 17/6/2026 | Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and… | |
| Modificada | Crítica (9.8) | 0.97% | — | Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+174 | 8/11/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy… | |
| Modificada | Alta (8.8) | 1.6% | — | Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware | 8/11/2022 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All versions < V3.10), SICAM P850 (All… | |
| Modificada | Alta (8.8) | 1.5% | — | Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware | 8/11/2022 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All versions < V3.10), SICAM P850 (All… | |
| Modificada | Alta (8.8) | 1.6% | — | Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware | 8/11/2022 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions < V2.50), SICAM… | |
| Modificada | Alta (8.8) | 0.52% | — | Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 Firmware | 8/11/2022 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie after login/logout and also accept user… | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+182 | 11/10/2022 | 17/6/2026 | Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | |
| Modificada | Alta (8) | 0.78% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. | |
| Modificada | Media (5.3) | 0.60% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. | |
| Modificada | Alta (7.8) | 0.24% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. | |
| Modificada | Media (6.8) | 0.23% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. | |
| Modificada | Media (5.3) | 0.75% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dahuasecurity Ipc-hx1xxx FirmwareDahuasecurity Ipc-hx2xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5(4)(3)xxx Firmware+24 | 13/1/2022 | 17/6/2026 | Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords. |