Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Amazonbasics FirmwareDell Km714 FirmwareDell Km632 FirmwareLogitech Unifying Firmware+12/8/201617/6/2026
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity…
ModificadaAlta (8.2)0.39%—Lenovo Bios EFI Driver30/6/201617/6/2026
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
ModificadaAlta (7.8)0.64%—Lenovo Solution Center30/6/201617/6/2026
Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Services.SystemService StartProxy command with a named pipe created in advance and crafted .NET assembly.
ModificadaMedia (5.5)0.30%—Lenovo Solution Center30/6/201617/6/2026
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.
ModificadaAlta (7.5)2.0%—Lenovo Accelerator Application3/6/201617/6/2026
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.
ModificadaMedia (6.1)0.77%—Lenovo Shareit23/5/201617/6/2026
Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
ModificadaAlta (8.8)1.9%—Lenovo Shareit23/5/201617/6/2026
Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack."
ModificadaMedia (5.3)1.5%—Lenovo EMC Firmware12/4/201617/6/2026
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
ModificadaAlta (7.8)0.32%—Lenovo Fingerprint ManagerLenovo Touch Fingerprint11/4/201617/6/2026
Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.
ModificadaAlta (7.5)3.3%—Cisco IOS XELenovo Thinkcentre E75s FirmwareSamsung X14j FirmwareSUN Opensolaris+226/3/201617/6/2026
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
ModificadaMedia (5.9)3.0%—Cisco IOS XELenovo Thinkcentre E75s FirmwareNetgear Jr6150 FirmwareSamsung X14j Firmware+326/3/201617/6/2026
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
ModificadaMedia (6.1)1.8%—Lenovo Shareit26/1/201617/6/2026
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
ModificadaAlta (8.8)2.5%—Lenovo Shareit26/1/201617/6/2026
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
ModificadaMedia (4.1)1.7%—Lenovo Shareit26/1/201617/6/2026
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.
ModificadaAlta (8)1.8%—Lenovo Shareit26/1/201617/6/2026
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
ModificadaAlta (7.1)1.4%—Lenovo Switch CenterIBM System Networking Switch Center12/11/201517/6/2026
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read…
ModificadaMedia (5)1.3%—Lenovo Switch CenterIBM System Networking Switch Center12/11/201517/6/2026
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.
ModificadaAlta (7.2)0.43%—IBM System Networking Switch CenterLenovo Switch Center12/11/201517/6/2026
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
ModificadaAlta (7.1)1.4%—IBM System Networking Switch CenterLenovo Switch Center12/11/201517/6/2026
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read…
ModificadaMedia (6.9)1.6%💥 ExploitQemuLinux KernelArista EOSDebian Linux+1531/8/201517/6/2026
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
ModificadaMedia (6.9)0.27%—Lenovo System Update12/5/201517/6/2026
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
ModificadaAlta (8.3)0.40%—Lenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
ModificadaAlta (7.2)4.1%💥 ExploitLenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
ModificadaMedia (4.3)0.47%—Lenovo Thinkserver System Manager Baseboard Management Controller Firmware16/4/201517/6/2026
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.
ModificadaMedia (5)1.3%—Lenovo Thinkserver System Manager Baseboard Management Controller Firmware16/4/201517/6/2026
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.