Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.81%—Ultimaker S3 FirmwareUltimaker S5 FirmwareUltimaker 3 Firmware10/1/202217/6/2026
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
ModificadaAlta (8.8)0.53%—Ultimaker S3 FirmwareUltimaker S5 FirmwareUltimaker 3 Firmware10/1/202217/6/2026
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify incoming requests.
ModificadaAlta (8.8)0.44%—Samsung Galaxy Watch Active 2 FirmwareSamsung Galaxy Watch Active FirmwareSamsung Galaxy Watch FirmwareSamsung Galaxy Watch 3 Firmware+511/6/202117/6/2026
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
ModificadaMedia (6.1)0.80%—NEC Aterm Wg1900hp2 FirmwareNEC Aterm Wg1900hp FirmwareNEC Aterm Wg1800hp4 FirmwareNEC Aterm Wg1800hp3 Firmware+1326/4/202117/6/2026
Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier, Aterm WG1800HP3 firmware Ver.1.5.1 and earlier, Aterm WG1200HS2 firmware Ver.2.5.0 and earlier, Aterm WG1200HP3…
ModificadaAlta (8)0.53%—Iptime Nas-i FirmwareIptime Nas-ii FirmwareIptime Nas-iie FirmwareIptime Nas101 Firmware+523/2/202117/6/2026
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
ModificadaAlta (7.8)0.51%—Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+10822/7/202017/6/2026
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
ModificadaMedia (6)0.55%—Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+12922/7/202017/6/2026
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
ModificadaMedia (6.8)0.30%—Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E15 FirmwareLenovo Thinkpad R14 FirmwareLenovo Thinkpad S3 GEN 2 Firmware+349/6/202017/6/2026
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
ModificadaMedia (6.7)0.33%—Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
ModificadaMedia (6.8)0.28%—Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+969/6/202017/6/2026
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
ModificadaMedia (4.6)0.39%—Simplisafe SS3 Firmware2/5/202017/6/2026
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.
ModificadaMedia (4.3)0.28%—Samsung S5 FirmwareSamsung Note3 FirmwareSamsung S4 FirmwareSamsung Note2 Firmware+17/4/202017/6/2026
An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).
ModificadaMedia (5.5)0.36%—Simplisafe SS3 Firmware13/2/202017/6/2026
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.
ModificadaCrítica (9.8)1.6%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModificadaMedia (6.5)0.81%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based…
ModificadaAlta (7.5)1.2%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
ModificadaAlta (7.5)1.4%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModificadaMedia (4.6)0.39%—Simplisafe SS3 Firmware16/1/202017/6/2026
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.
ModificadaMedia (4.3)0.29%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
ModificadaMedia (4.6)0.35%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.5)0.51%—Samsung Galaxy S8 Plus FirmwareSamsung Galaxy S3 FirmwareSamsung Galaxy Note 2 Firmware6/11/201917/6/2026
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: I9300XXUGNA8), and Samsung Galaxy Note 2…
ModificadaMedia (6.5)0.46%—Samsung Galaxy S8 Plus FirmwareSamsung Galaxy S3 FirmwareSamsung Galaxy Note 2 Firmware6/11/201917/6/2026
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: I9300XXUGNA8), and Samsung Galaxy Note 2…