Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. | |
| Modificada | Alta (7.5) | 1.3% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks. | |
| Modificada | Alta (7.5) | 1.2% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling. | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens KTK Ate530s FirmwareSiemens Sidoor Atd430w FirmwareSiemens Sidoor Ate530s Coated FirmwareSiemens Sidoor Ate531s Firmware+29 | 14/4/2020 | 17/6/2026 | A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L… | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens Simatic S7-300 CPU FirmwareSiemens Simatic S7-300 CPU 312 IFM FirmwareSiemens Simatic S7-300 CPU 313 FirmwareSiemens Simatic S7-300 CPU 314 Firmware+8 | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions < V4.94).… | |
| Modificada | Media (5.1) | 0.28% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Alta (7.8) | 0.33% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+4 | 14/11/2019 | 17/6/2026 | Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.27% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.27% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Alta (8.2) | 0.33% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.56% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access. | |
| Modificada | Media (6.7) | 0.32% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access. | |
| Modificada | Alta (7.5) | 1.3% | — | Siemens Simatic TDC Cp51m1 Firmware | 13/9/2019 | 17/6/2026 | A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could cause a Denial-of-Service condition by sending a specially crafted UDP packet. The vulnerability affects the UDP communication of the device. The security vulnerability could be… | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | ZTE Mf65 FirmwareZTE Mf65m1 Firmware | 26/9/2018 | 17/6/2026 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices. | |
| Modificada | Media (4.3) | 0.35% | — | Cisco 5400 Enterprise Network Compute System FirmwareCisco 5100 Enterprise Network Compute System FirmwareCisco Ucs-e160s-m3 FirmwareCisco Ucs-e160s-k9 Firmware+17 | 21/6/2018 | 17/6/2026 | A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper… | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. |