Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is…
ModificadaAlta (8.8)1.8%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions…
ModificadaAlta (7.5)1.0%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The overflowed data…
ModificadaCrítica (10)1.6%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the…
ModificadaAlta (7.5)0.96%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP…
ModificadaCrítica (9.8)2.4%—Hidglobal Lp1501 FirmwareHidglobal Lp1502 FirmwareHidglobal Lp2500 FirmwareHidglobal Lp4502 Firmware+106/6/202217/6/2026
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware…
ModificadaMedia (6.5)0.49%💥 PoCZyxel Ax7501-b0 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx5401-b0 FirmwareZyxel Emg3525-t50b Firmware+271/3/202217/6/2026
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
ModificadaMedia (6.4)0.23%—Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+1414/10/202017/6/2026
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
ModificadaAlta (7.5)1.3%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+3822/4/201917/6/2026
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
ModificadaMedia (4.9)0.66%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X440 M4 FirmwareLenovo System X3750 M4 FirmwareIBM Bladecenter Hs23 Firmware+2516/11/201817/6/2026
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
ModificadaAlta (7.5)1.1%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+3826/7/201817/6/2026
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and…
ModificadaAlta (7.5)1.2%—Lenova Flex System X240 M5 FirmwareLenova Flex System X280 X6 FirmwareLenova Flex System X440 M4 FirmwareLenova Flex System X480 X6 Firmware+3826/1/201817/6/2026
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI…
ModificadaMedia (4.3)0.95%—IBM Integrated Management Module 2IBM BladecenterIBM Flex System Manager Node 7955IBM Flex System Manager Node 8731+2721/1/201416/6/2026
Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.
ModificadaAlta (10)3.8%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
ModificadaMedia (5)2.4%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
Orbitaley — Vulnerabilidades