Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Cisco Sf200-24 FirmwareCisco Sf200-24p FirmwareCisco Sf200-48 FirmwareCisco Sf200-48p Firmware+53 | 6/7/2019 | 17/6/2026 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web interface. An attacker… | |
| Modificada | Alta (7.7) | 2.0% | — | Cisco Sf200-24 FirmwareCisco Sf200-24p FirmwareCisco Sf200-48 FirmwareCisco Sf200-48p Firmware+101 | 15/5/2019 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attacker to cause the SNMP application of an affected device to… | |
| Modificada | Alta (8.8) | 2.7% | — | Edimax Ic-3140w FirmwareEdimax Ic-5150w FirmwareEdimax Ic-6220dc Firmware | 26/4/2018 | 17/6/2026 | An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the… | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Sg350-10 FirmwareCisco Sg350-10p FirmwareCisco Sg350-10mp FirmwareCisco Sg355-10p Firmware+81 | 18/1/2018 | 17/6/2026 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters… | |
| Modificada | Media (6.1) | 0.87% | — | Cisco Sg350-10 FirmwareCisco Sg350-10p FirmwareCisco Sg350-10mp FirmwareCisco Sg355-10p Firmware+81 | 18/1/2018 | 17/6/2026 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of… | |
| Modificada | Crítica (9.8) | 2.8% | — | Korenix Jetnet5018g FirmwareKorenix Jetnet5310g FirmwareKorenix Jetnet5428g-2g-2fx FirmwareKorenix Jetnet5628g Firmware+5 | 1/11/2017 | 17/6/2026 | A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version… | |
| Modificada | Crítica (9.8) | 1.9% | — | Korenix Jetnet5018g FirmwareKorenix Jetnet5310g FirmwareKorenix Jetnet5428g-2g-2fx FirmwareKorenix Jetnet5628g Firmware+5 | 1/11/2017 | 17/6/2026 | A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Sf302-08pp FirmwareCisco Sf302-08mpp FirmwareCisco Sg300-10pp FirmwareCisco Sg300-10mpp Firmware+81 | 21/9/2017 | 17/6/2026 | A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker… | |
| Modificada | Media (4.3) | 1.4% | — | Fortinet Fortiadc FirmwareFortinet Fortiadc-1500dFortinet Fortiadc-2000dFortinet Fortiadc-200d+2 | 12/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 1.3% | — | Fortinet Coyote Point Equalizer FirmwareFortinet Coyote Point EqualizerFortinet Fortiadc FirmwareFortinet Fortiadc-1000e+3 | 1/11/2014 | 17/6/2026 | FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote attackers to obtain access to arbitrary subnets via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Fortinet Fortiadc FirmwareFortinet Fortiadc-1000eFortinet Fortiadc-1500dFortinet Fortiadc-2000d+5 | 10/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale parameter to gui_partA/. |