Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.68% | — | Wavlink Wl-wn531ax2 Firmware | 30/6/2023 | 17/6/2026 | Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege. | |
| Modificada | Media (4.7) | 0.81% | — | Ieee 802.2Ietf P802.1qCisco Catalyst 6503-e FirmwareCisco Catalyst 6504-e Firmware+92 | 27/9/2022 | 17/6/2026 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | |
| Modificada | Media (5.4) | 0.35% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail. | |
| Modificada | Alta (8.1) | 0.67% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM. | |
| Modificada | Media (6.5) | 0.66% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information. | |
| Modificada | Media (4.2) | 0.47% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information. | |
| Modificada | Alta (8.8) | 0.40% | — | Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+140 | 25/8/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Nexus 3016 FirmwareCisco Nexus 3016q FirmwareCisco Nexus 3048 FirmwareCisco Nexus 3064 Firmware+143 | 25/8/2022 | 17/6/2026 | A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this… | |
| Modificada | Media (5.6) | 0.50% | — | XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+18 | 13/3/2022 | 17/6/2026 | Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive… | |
| Modificada | Media (4.7) | 0.30% | — | Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+18 | 10/3/2022 | 17/6/2026 | Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to… | |
| Modificada | Crítica (9.8) | 4.8% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands. | |
| Modificada | Media (5.3) | 1.3% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication. | |
| Modificada | Crítica (9.8) | 4.4% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.6% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed. | |
| Modificada | Alta (7.5) | 1.5% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package. | |
| Modificada | Media (5.3) | 1.3% | — | Motorola CX2 Firmware | 21/7/2021 | 17/6/2026 | A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid. | |
| Modificada | Alta (7.5) | 1.1% | — | Jtekt Pc10g-cpu FirmwareJtekt 2port-efr FirmwareJtekt Plus CPU FirmwareJtekt Plus EX Firmware+18 | 1/7/2021 | 17/6/2026 | When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a… | |
| Modificada | Media (6.5) | 0.70% | — | Philips Patient Information Center IXPhilips Performancebridge Focal PointPhilips Intellivue Mp2-mp90 FirmwarePhilips Intellivue Mx100 Firmware+9 | 11/9/2020 | 17/6/2026 | In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly, which can… | |
| Modificada | Media (6.4) | 0.37% | — | Philips Patient Information Center IXPhilips Performancebridge Focal PointPhilips Intellivue Mp2-mp90 FirmwarePhilips Intellivue Mx100 Firmware+9 | 11/9/2020 | 17/6/2026 | In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation status of a certificate, which may cause it… | |
| Modificada | Alta (8.8) | 0.58% | — | Plathome Openblocks IOT VX2 Firmware | 4/3/2020 | 17/6/2026 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the device via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.85% | — | Plathome Openblocks IOT VX2 Firmware | 4/3/2020 | 17/6/2026 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors. | |
| Modificada | Media (6.1) | 0.86% | — | Lenovo EZ Media & Backup Center IX2 FirmwareLenovo EZ Media & Backup Center Ix2-dl Firmware | 14/2/2020 | 17/6/2026 | A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page. | |
| Modificada | Alta (7.2) | 0.69% | — | Philips Intellivue MP Monitors Mp20-mp90 FirmwarePhilips Intellivue MP Monitors Mp5/5sc FirmwarePhilips Intellivue MP Monitors Mp2/x2 FirmwarePhilips Intellivue MP Monitors Mx800/700/600 Firmware | 12/9/2019 | 17/6/2026 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). The product downloads source code… | |
| Modificada | Alta (7.2) | 1.4% | — | Philips Intellivue MP Monitors Mp20-mp90 FirmwarePhilips Intellivue MP Monitors Mp5/5sc FirmwarePhilips Intellivue MP Monitors Mp2/x2 FirmwarePhilips Intellivue MP Monitors Mx800/700/600 Firmware | 12/9/2019 | 17/6/2026 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). An attacker can use these… | |
| Modificada | Crítica (9.8) | 1.7% | — | Motorola CX2 FirmwareMotorola M2 Firmware | 23/5/2019 | 17/6/2026 | An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080. |