Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.2%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.2%—Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+406/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.2%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.8%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.9%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaMedia (4.9)1.9%—Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware6/4/202117/6/2026
The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
ModificadaAlta (8.8)1.3%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
ModificadaMedia (5.4)0.52%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
Orbitaley — Vulnerabilidades