Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.43% | — | Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+38 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an… | |
| Analizada | Alta (7.5) | 0.66% | — | Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+46 | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Modificada | Alta (7.5) | 0.19% | — | Omron Nj101-1000 FirmwareOmron Nj101-1020 FirmwareOmron Nj101-9000 FirmwareOmron Nj101-9020 Firmware+51 | 24/6/2024 | 17/6/2026 | Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration. | |
| Analizada | Media (5.5) | 0.14% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 Firmware+61 | 21/5/2024 | 17/6/2026 | The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. | |
| Analizada | Media (6.5) | 0.55% | — | Zyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510 FirmwareZyxel Dx5401-b0 Firmware+28 | 21/5/2024 | 17/6/2026 | The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Modificada | Crítica (9.8) | 0.69% | — | Connectedio Er2000t-vz-cat1 Firmware | 4/8/2023 | 17/6/2026 | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices. | |
| Modificada | Crítica (9.8) | 1.4% | — | Omron Cs1w-eip21 FirmwareOmron Cs1w-spu01-v2 FirmwareOmron Cs1w-spu02-v2 FirmwareOmron Cs1w-etn21 Firmware+267 | 19/6/2023 | 17/6/2026 | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext… | |
| Modificada | Media (5.9) | 1.9% | 💥 PoC | Sinilink Xy-wft1 Firmware | 20/1/2023 | 17/6/2026 | The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024) commands interfacing directly with the target device. This, in turn, allows for an attack to… | |
| Modificada | Media (6.5) | 0.62% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. | |
| Modificada | Media (6.5) | 0.72% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.1% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+35 | 11/1/2023 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. | |
| Modificada | Media (6.1) | 0.90% | — | Mitsubishielectric Mac-587if-e FirmwareMitsubishielectric Mac-587if2-e FirmwareMitsubishielectric Mac-507if-e FirmwareMitsubishielectric Mac-588if-e Firmware+115 | 8/11/2022 | 17/6/2026 | Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and… | |
| Modificada | Crítica (9.8) | 0.97% | — | Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+174 | 8/11/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy… | |
| Modificada | Crítica (9.8) | 63% | 💥 Exploit | Dlink Dir-615 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-615 T1 FirmwareDlink Dir-615jx10 Firmware | 23/8/2022 | 9/7/2026 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page. | |
| Modificada | Alta (8.1) | 1.3% | — | Omron Nx701-1600 FirmwareOmron Nx701-1700 FirmwareOmron Nx701-z700 FirmwareOmron Nx701-z600 Firmware+53 | 4/7/2022 | 17/6/2026 | Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49… | |
| Modificada | Alta (7.5) | 1.2% | — | Omron Nx701-1600 FirmwareOmron Nx701-1700 FirmwareOmron Nx701-z700 FirmwareOmron Nx701-z600 Firmware+48 | 4/7/2022 | 17/6/2026 | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker… | |
| Modificada | Alta (8.1) | 1.9% | — | Omron Nx701-1600 FirmwareOmron Nx701-1700 FirmwareOmron Nx701-z700 FirmwareOmron Nx701-z600 Firmware+53 | 4/7/2022 | 17/6/2026 | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all… | |
| Modificada | Alta (7.4) | 0.98% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the user's login packet. | |
| Modificada | Media (4.7) | 0.71% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page. | |
| Modificada | Media (5.9) | 0.76% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the user's login packet. | |
| Modificada | Alta (7.4) | 0.85% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafted packet to the vulnerable interface then lead the device to crash. | |
| Modificada | Alta (8) | 0.79% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. | |
| Modificada | Media (5.3) | 0.59% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. | |
| Modificada | Alta (7.8) | 0.24% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. | |
| Modificada | Media (6.8) | 0.23% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. |