Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.26% | — | Lenovo Stadia Ggp-120 FirmwareLenovo Thinkedge Se30 FirmwareLenovo V540-24iwl FirmwareLenovo Thinkstation P520 Firmware+28 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (5.6) | 0.50% | — | XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+18 | 13/3/2022 | 17/6/2026 | Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive… | |
| Modificada | Media (4.7) | 0.30% | — | Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+18 | 10/3/2022 | 17/6/2026 | Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to… | |
| Modificada | Alta (7.5) | 1.0% | — | Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+10 | 11/2/2022 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H),… | |
| Modificada | Alta (7.5) | 1.0% | — | Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+10 | 11/2/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules:… | |
| Modificada | Alta (7.5) | 0.96% | — | Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+10 | 11/2/2022 | 17/6/2026 | A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet… | |
| Modificada | Media (6.7) | 0.25% | — | Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M600 FirmwareLenovo Thinkcentre M700 Tiny FirmwareLenovo Thinkcentre M73 Firmware+16 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.5% | — | Phoenixcontact Ilc1x0 FirmwarePhoenixcontact Ilc1x1 Firmware | 25/6/2021 | 17/6/2026 | Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's… | |
| Modificada | Media (6.8) | 0.48% | — | Foscammall Foscam X1 Firmware | 28/12/2020 | 17/6/2026 | FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password. | |
| Modificada | Media (6.7) | 0.32% | — | Intel Nuc8i7behga FirmwareIntel Nuc8i7bekqa FirmwareIntel Nuc8i3behfa FirmwareIntel Nuc8i5behfa Firmware+69 | 13/8/2020 | 17/6/2026 | Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.4% | — | Panasonic Eluga RAY 530 FirmwarePanasonic Eluga RAY 600 FirmwarePanasonic P110 FirmwarePanasonic Eluga Z1 PRO Firmware+2 | 20/5/2020 | 17/6/2026 | Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support." | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 22/4/2020 | 17/6/2026 | A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an… | |
| Modificada | Media (6.5) | 1.6% | — | Amcrest 1080-lite 8CH FirmwareAmcrest Amdv10814-h5 FirmwareAmcrest Ipm-721 FirmwareAmcrest Ip2m-841 Firmware+14 | 8/4/2020 | 17/6/2026 | Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device. | |
| Analizada | Alta (8.8) | 36% | ⚠ Explotación activa💥 Exploit | Amcrest 1080-lite 8CH FirmwareAmcrest Amdv10814-h5 FirmwareAmcrest Ipm-721 FirmwareAmcrest Ip2m-841 Firmware+14 | 8/4/2020 | 17/6/2026 | Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+66 | 12/3/2020 | 17/6/2026 | Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html | |
| Modificada | Media (6.7) | 0.34% | — | Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+66 | 12/3/2020 | 17/6/2026 | Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html | |
| Modificada | Alta (7.5) | 1.4% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 20/11/2019 | 17/6/2026 | A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials… | |
| Modificada | Media (6.7) | 0.45% | — | Nvidia Jetson TX1 Firmware | 19/7/2019 | 17/6/2026 | In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. | |
| Modificada | Alta (7.8) | 0.32% | — | Nvidia Jetson TX1 FirmwareNvidia Jetson TK1 FirmwareNvidia Tegra K1 Firmware | 26/3/2018 | 17/6/2026 | NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or write a buffer using an index or pointer that references a memory location after the end of the buffer, which may lead to a denial of service or possible escalation of privileges. | |
| Modificada | Media (6.8) | 0.66% | — | Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+41 | 8/2/2018 | 17/6/2026 | Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (6.1) | 0.82% | — | Dell EMC Vnx2 FirmwareDell EMC Vnx1 Firmware | 4/1/2018 | 17/6/2026 | In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this… | |
| Modificada | Alta (7.8) | 0.36% | — | Nvidia Tegra X1 Firmware | 16/11/2017 | 17/6/2026 | An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android… | |
| Modificada | Baja (3.7) | 1.5% | — | Seil B1 FirmwareSeil BPV 4 FirmwareSeil X1 FirmwareSeil X2 Firmware+1 | 15/9/2017 | 17/6/2026 | SEIL/X 4.60 to 5.72, SEIL/B1 4.60 to 5.72, SEIL/x86 3.20 to 5.72, SEIL/BPV4 5.00 to 5.72 allows remote attackers to cause a temporary failure of the device's encrypted communications via a specially crafted packet. |