Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.26%—Nissan-global Blind Spot Detection Sensor ECU Firmware15/8/202417/6/2026
—
ModificadaAlta (8.3)0.23%—Proges Sensor NET Connect Firmware V231/7/202417/6/2026
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.
ModificadaMedia (4.6)0.11%—Proges Sensor NET Connect Firmware V231/7/202417/6/2026
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.
AnalizadaMedia (4.6)0.19%—Proges Sensor NET Connect Firmware V231/7/202417/6/2026
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.
ModificadaMedia (6.1)0.32%—Proges Sensor NET Connect Firmware V231/7/202417/6/2026
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.
ModificadaMedia (6.4)0.41%—Goodix Fingerprint Sensor Firmware9/12/202317/6/2026
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling…
ModificadaAlta (7.8)0.21%—Ellipticlabs AI Virtual Presence SensorEllipticlabs Virtual Lock Sensor25/10/202317/6/2026
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
ModificadaAlta (7.8)0.21%—Digitalpersona Fpsensor Project Digitalpersona Fpsensor11/5/202317/6/2026
A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773…
ModificadaMedia (4.4)0.22%—Intel Integrated Sensor Solution16/2/202317/6/2026
Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)55%—Keysight Sensor Management Server10/8/202217/6/2026
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e.,…
AnalizadaCrítica (9.8)21%—Keysight Sensor Management Server10/8/202217/6/2026
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.
ModificadaCrítica (10)6.2%—Swiftsensors Sg3-1010 Firmware14/4/202217/6/2026
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaMedia (5.9)1.9%—Microsoft Defender FOR Endpoint EDR SensorMicrosoft Defender FOR Endpoint9/3/202217/6/2026
Microsoft Defender for Endpoint Spoofing Vulnerability
AnalizadaCrítica (9)100%⚠ Explotación activaApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5114/12/202117/6/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
AnalizadaCrítica (10)100%⚠ Explotación activaSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaAlta (7.8)0.23%—Intel NUC M15 Laptop KIT Integrated Sensor HUB Driver Pack17/11/202117/6/2026
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)3.2%—Akcp Sensorprobe2 FirmwareAkcp Sensorprobe4 FirmwareAkcp Sensorprobe8 FirmwareAkcp Sensorprobe8-x20 Firmware+130/6/202117/6/2026
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
ModificadaAlta (7)1.9%—Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+420/2/202017/6/2026
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by…
ModificadaCrítica (9.8)3.6%—Kentix Multisensor-lan Firmware21/3/201917/6/2026
Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel.
ModificadaAlta (7.5)2.6%—Cisco Aironet Active SensorCisco Digital Network Architecture Center7/2/201917/6/2026
A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static password. The account has privileges only to reboot the device. An attacker could exploit this…
ModificadaMedia (6.5)0.62%—Qbeecam Qbee Multi-sensor Camera FirmwareQbeecamSwisscom Home APP18/9/201817/6/2026
The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.
ModificadaAlta (7.5)2.2%—Wpitchoune PsensorDebian Linux20/4/201817/6/2026
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
ModificadaAlta (7)1.6%—Trendmicro Deep SecurityTrendmicro Endpoint SensorTrendmicro OfficescanTrendmicro Security+116/2/201817/6/2026
A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.
ModificadaAlta (7.8)0.30%—Sierrawireless Sierra Wireless Em7345 SoftwareSierrawireless Sierra Wireless Em7455 SoftwareSierrawireless Sierra Wireless Location Sensor Driver2/8/201717/6/2026
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges.
ModificadaCrítica (9.8)1.8%—Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+1830/6/201717/6/2026
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow…