Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.88% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),… | |
| Modificada | Media (5.1) | 1.0% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again. | |
| Modificada | Media (4.3) | 0.64% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <… | |
| Modificada | Media (6.9) | 0.45% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),… | |
| Modificada | Media (6.9) | 0.69% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the device. This could allow an authenticated attacker with administrative privileges or an attacker that obtains a configuration backup to extract configuration information from the exported file. | |
| Modificada | Alta (7.5) | 0.78% | — | Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+5 | 10/10/2023 | 17/6/2026 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a… | |
| Modificada | Media (6.5) | 0.31% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+116 | 11/4/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the… | |
| Modificada | Media (4.8) | 0.50% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+46 | 11/4/2023 | 17/6/2026 | Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network… | |
| Modificada | Media (6.5) | 0.62% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. | |
| Modificada | Media (6.5) | 0.72% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.1% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+35 | 11/1/2023 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. | |
| Modificada | Alta (7.5) | 0.62% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products… | |
| Modificada | Media (5.3) | 0.69% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an… | |
| Modificada | Crítica (9.8) | 1.0% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of… | |
| Modificada | Alta (7.5) | 0.68% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted… | |
| Modificada | Media (5.5) | 0.23% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted… | |
| Modificada | Media (6.1) | 0.46% | — | Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+1 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The integrated web… | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+182 | 11/10/2022 | 17/6/2026 | Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | Patlite Nhp-fb2 FirmwarePatlite Nhl-fb2 Firmware | 27/7/2022 | 17/6/2026 | On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced. | |
| Modificada | Media (5.5) | 0.21% | — | Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+28 | 11/4/2022 | 17/6/2026 | A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service. | |
| Modificada | Alta (8) | 0.70% | — | Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+28 | 11/4/2022 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface. | |
| Modificada | Media (6.5) | 0.49% | 💥 PoC | Zyxel Ax7501-b0 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx5401-b0 FirmwareZyxel Emg3525-t50b Firmware+27 | 1/3/2022 | 17/6/2026 | A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file. | |
| Modificada | Alta (7.5) | 6.7% | — | StrongswanDebian LinuxFedoraproject FedoraSiemens 6gk6108-4am00-2ba2 Firmware+16 | 18/10/2021 | 17/6/2026 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric Qj71e71-100 FirmwareMitsubishielectric Qj71e71-b5 FirmwareMitsubishielectric Qj71e71-b2 Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. Weakly encrypted passwords are transmitted to a MELSEC-Q PLC. | |
| Modificada | Alta (8.6) | 2.6% | — | Mitsubishielectric Qj71e71-100 FirmwareMitsubishielectric Qj71e71-b5 FirmwareMitsubishielectric Qj71e71-b2 Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to a MELSEC-Q PLC, which may allow a remote attacker to connect to the PLC via Port… |