Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
ModificadaAlta (7.5)1.3%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
ModificadaAlta (7.5)1.7%—Siemens KTK Ate530s FirmwareSiemens Sidoor Atd430w FirmwareSiemens Sidoor Ate530s Coated FirmwareSiemens Sidoor Ate531s Firmware+2914/4/202017/6/2026
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L…
ModificadaAlta (7.5)1.7%—Siemens Simatic S7-300 CPU FirmwareSiemens Simatic S7-300 CPU 312 IFM FirmwareSiemens Simatic S7-300 CPU 313 FirmwareSiemens Simatic S7-300 CPU 314 Firmware+810/3/202017/6/2026
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions < V4.94).…
ModificadaMedia (5.1)0.28%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.29%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.29%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.29%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.29%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaAlta (7.8)0.33%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+414/11/201917/6/2026
Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.5)0.27%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.27%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaAlta (8.2)0.33%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.56%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.
ModificadaMedia (6.7)0.32%—Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+314/11/201917/6/2026
Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access.
ModificadaAlta (7.5)1.3%—Siemens Simatic TDC Cp51m1 Firmware13/9/201917/6/2026
A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could cause a Denial-of-Service condition by sending a specially crafted UDP packet. The vulnerability affects the UDP communication of the device. The security vulnerability could be…
ModificadaMedia (6.1)1.9%💥 ExploitZTE Mf65 FirmwareZTE Mf65m1 Firmware26/9/201817/6/2026
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices.
ModificadaMedia (4.3)0.35%—Cisco 5400 Enterprise Network Compute System FirmwareCisco 5100 Enterprise Network Compute System FirmwareCisco Ucs-e160s-m3 FirmwareCisco Ucs-e160s-k9 Firmware+1721/6/201817/6/2026
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper…
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaAlta (7.1)1.1%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+8911/5/201717/6/2026
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.