Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.2% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.2% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.2% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Alta (8.8) | 1.3% | — | HPE KVM IP Console Switch G2 Firmware | 2/10/2020 | 17/6/2026 | A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. | |
| Modificada | Media (5.4) | 0.52% | — | HPE KVM IP Console Switch G2 Firmware | 2/10/2020 | 17/6/2026 | A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. |