Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.9% | — | Fujitsu Esprimo D556/2 FirmwareFujitsu Esprimo D6011 FirmwareFujitsu Esprimo D6012 FirmwareFujitsu Esprimo D7010 Firmware+183 | 7/12/2023 | 17/6/2026 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of… | |
| Modificada | Media (6.1) | 0.48% | — | Cisco Encs 5100 FirmwareCisco Encs 5400 FirmwareCisco UCS C220 M5 Rack Server FirmwareCisco UCS E160s M3 Firmware+2 | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Tenda M3 Firmware | 28/8/2022 | 17/6/2026 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo. | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData. | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm. | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient. | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb. | |
| Modificada | Alta (7.5) | 15% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda M3 Firmware | 1/7/2022 | 17/6/2026 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist. | |
| Modificada | Crítica (9.8) | 2.8% | — | Tenda M3 Firmware | 24/3/2022 | 17/6/2026 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic. | |
| Modificada | Crítica (9.8) | 2.7% | — | Tenda M3 Firmware | 24/3/2022 | 17/6/2026 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo. | |
| Modificada | Crítica (9.8) | 2.6% | — | Tenda M3 Firmware | 24/3/2022 | 17/6/2026 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo. | |
| Modificada | Crítica (9.8) | 2.6% | — | Tenda M3 Firmware | 24/3/2022 | 17/6/2026 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode. |