Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
882 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Publishpress SeriesAI | 18/8/2026 | 20/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Steelseries GGAISteelseries Libssedevice.dylibAI | 17/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components | |
| Aplazada | Crítica (9.8) | 0.80% | — | Steelseries GGAI | 17/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components | |
| Analizada | Alta (8.3) | 0.14% | 💥 PoC | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Analizada | Media (6.5) | 0.64% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 5/8/2026 | 16/9/2026 | — | |
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI | 4/8/2026 | 4/8/2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN… | |
| Pendiente de análisis | Alta (8.3) | 0.58% | — | Eaton Tripp Lite Series PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Pendiente de análisis | Media (6.9) | 0.54% | — | Honeywell S35 Series CameraAIHoneywell 3M CameraAIHoneywell 5M CameraAIHoneywell 8M CameraAI+1 | 27/7/2026 | 3/9/2026 | Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends… | |
| Aplazada | Alta (8.7) | 0.64% | — | Mitsubishielectric Melsec Iq-f Series Fx5-enet/ipAI | 19/6/2026 | 22/6/2026 | Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of… | |
| Aplazada | Alta (8.7) | 0.64% | — | Mitsubishielectric Melsec Iq-f Series Fx5-eipAI | 19/6/2026 | 22/6/2026 | Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP… | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI | 29/5/2026 | 21/7/2026 | Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800… | |
| Aplazada | Alta (8.7) | 0.56% | — | Slican IPX SeriesAISlican Cct-1668AISlican Mac-6400AISlican Cxs-0424AI | 27/5/2026 | 17/6/2026 | In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version… | |
| Aplazada | Crítica (9.3) | 0.58% | — | Slican NCPAISlican IPX SeriesAISlican Cct-1668AISlican Mac-6400AI+1 | 27/5/2026 | 17/6/2026 | Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue was fixed in versions below: - NCP: version 1.24.0250 - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400:… | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAI | 20/5/2026 | 23/7/2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel Ethernet 800 SeriesAI | 12/5/2026 | 17/6/2026 | Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Pendiente de análisis | Alta (7.7) | 0.39% | — | Cisco 350 Series Managed SwitchesAICisco 350x Series Stackable Managed SwitchesAI | 6/5/2026 | 17/6/2026 | This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a… | |
| Analizada | Alta (7.7) | 0.81% | — | Redistimeseries | 5/5/2026 | 25/7/2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can… | |
| Analizada | Crítica (9.8) | 0.68% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 22/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access… | |
| Analizada | Media (6.7) | 0.19% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 1.4% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root… | |
| Analizada | Alta (7.2) | 1.2% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 0.42% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (7.2) | 0.44% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… |