Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.17% | — | Intel Server Board S1200v3rpl FirmwareIntel Server Board S1200v3rpm FirmwareIntel Server Board S1200v3rpo FirmwareIntel Server Board S1200v3rps Firmware+60 | 12/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.91% | — | Phoenixcontact FL Mguard Centerport FirmwarePhoenixcontact FL Mguard Centerport Vpn-1000 FirmwarePhoenixcontact FL Mguard Core TX FirmwarePhoenixcontact FL Mguard Core TX VPN Firmware+27 | 15/11/2022 | 17/6/2026 | A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue. | |
| Modificada | Media (6.1) | 0.90% | — | Mitsubishielectric Mac-587if-e FirmwareMitsubishielectric Mac-587if2-e FirmwareMitsubishielectric Mac-507if-e FirmwareMitsubishielectric Mac-588if-e Firmware+115 | 8/11/2022 | 17/6/2026 | Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and… | |
| Modificada | Crítica (9.8) | 0.97% | — | Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+174 | 8/11/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy… | |
| Modificada | Alta (8) | 0.79% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. | |
| Modificada | Media (5.3) | 0.59% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. | |
| Modificada | Alta (7.8) | 0.24% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. | |
| Modificada | Media (6.8) | 0.23% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. | |
| Modificada | Media (5.3) | 0.74% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. | |
| Modificada | Alta (8.8) | 0.45% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+19 | 31/3/2022 | 17/6/2026 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware… | |
| Modificada | Media (4.9) | 0.69% | — | Fujifilm Apeosport-iv 7080 FirmwareFujifilm Apeosport-iv 6080 FirmwareFujifilm Apeosport-iv 5080 FirmwareFujifilm Apeosport-iv 3065 Firmware+156 | 3/3/2022 | 17/6/2026 | A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on… | |
| Modificada | Alta (8.8) | 0.52% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11… | |
| Modificada | Alta (8) | 0.86% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11… | |
| Modificada | Media (4.3) | 0.38% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11… | |
| Modificada | Alta (8.8) | 0.46% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware… | |
| Modificada | Alta (8.8) | 0.55% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV… | |
| Modificada | Alta (8) | 0.56% | — | Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+10 | 1/12/2021 | 17/6/2026 | ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware… | |
| Modificada | Media (6.7) | 0.25% | — | Intel Ethernet Controller V710-at2 FirmwareIntel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 Firmware+7 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in the firmware for Intel(R) Ethernet 700 Series Controllers before version 8.2 may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Hikvision Ds-2cd2026g2-iu/sl FirmwareHikvision Ds-2cd2046g2-iu/sl FirmwareHikvision Ds-2cd2066g2-i(u) FirmwareHikvision Ds-2cd2066g2-iu/sl Firmware+252 | 22/9/2021 | 17/6/2026 | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands. | |
| Modificada | Alta (7.3) | 0.72% | — | Phoenixcontact AXL F BK PN TPS XC FirmwarePhoenixcontact AXL F BK PN TPS FirmwarePhoenixcontact AXL F BK EIP FirmwarePhoenixcontact AXL F BK EIP EF Firmware+14 | 25/6/2021 | 17/6/2026 | In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists. | |
| Modificada | Alta (7.5) | 4.9% | — | Mitsubishielectric R00cpu FirmwareMitsubishielectric R01cpu FirmwareMitsubishielectric R02cpu FirmwareMitsubishielectric R04cpu Firmware+24 | 20/11/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version '25' and earlier, R08/16/32/120PSFCPU… | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.38% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Protection mechanism failure in Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. |