Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | |
| Analizada | Media (4.9) | 0.58% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | |
| Analizada | Media (4.9) | 0.55% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. | |
| Modificada | Crítica (9.4) | 3.4% | — | Edimax Ew-7438rpn Mini Firmware | 20/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly,… | |
| Modificada | Crítica (9.4) | 3.8% | — | Edimax Ew-7438rpn Mini Firmware | 20/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary… | |
| Modificada | Alta (7.5) | 0.63% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | |
| Modificada | Crítica (9.8) | 0.80% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | |
| Modificada | Alta (7.8) | 0.09% | — | Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+11 | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | |
| Modificada | Alta (7.8) | 0.31% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | |
| Modificada | Media (5.9) | 0.19% | — | Google Nest Mini FirmwareHaxx Libcurl | 19/8/2024 | 17/6/2026 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Modificada | Crítica (9.8) | 0.24% | — | Google Nest Audio FirmwareGoogle Nest Mini FirmwareGoogle Home Mini FirmwareGoogle Home Firmware | 2/1/2024 | 17/6/2026 | An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege | |
| Modificada | Crítica (9.8) | 75% | — | Carel Boss Mini Firmware | 12/7/2023 | 17/6/2026 | A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7) | 0.13% | — | HP 260 G4 Desktop Mini FirmwareHP T430 FirmwareHP T628 FirmwareHP 240 G10 Firmware+55 | 30/6/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (8.8) | 0.32% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files. | |
| Modificada | Crítica (9.8) | 0.46% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | |
| Modificada | Media (4.2) | 0.27% | — | Onekey Touch FirmwareOnekey Mini Firmware | 14/2/2023 | 17/6/2026 | Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the… |