Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.30% | — | Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware | 10/5/2023 | 17/6/2026 | An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. | |
| Modificada | Media (5.5) | 0.14% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+55 | 10/5/2023 | 17/6/2026 | Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.1) | 0.56% | — | Westerndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home Firmware | 10/5/2023 | 17/6/2026 | A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to… | |
| Modificada | Media (4.3) | 0.46% | — | Westerndigital MY CloudWesterndigital MY Cloud HomeWesterndigital MY Cloud OS 5Westerndigital Sandisk IBI | 8/5/2023 | 17/6/2026 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing… | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+161 | 2/5/2023 | 17/6/2026 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | |
| Modificada | Crítica (9.8) | 0.71% | — | Home.cern White Rabbit Switch Firmware | 24/4/2023 | 17/6/2026 | White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user). | |
| Modificada | Alta (7.5) | 0.75% | — | Home.cern White Rabbit Switch Firmware | 24/4/2023 | 17/6/2026 | Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings. | |
| Modificada | Alta (8.8) | 0.66% | — | Schneider-electric Insighthome FirmwareSchneider-electric Insightfacility FirmwareSchneider-electric Conext Gateway Firmware | 18/4/2023 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute. | |
| Modificada | Media (4.8) | 0.39% | — | Magneticlab Homepage Pop-up | 16/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Crítica (10) | 72% | 💥 Exploit | Home-assistantHome-assistant Supervisor | 8/3/2023 | 17/6/2026 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home… | |
| Modificada | Crítica (9.8) | 0.76% | — | Znfit Home Improvement ERP Management System | 21/2/2023 | 17/6/2026 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet. | |
| Modificada | Alta (7.8) | 0.15% | — | Acronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home Office | 13/2/2023 | 17/6/2026 | Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984. | |
| Modificada | Media (5.5) | 0.16% | — | Dell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information. | |
| Modificada | Media (5.3) | 0.44% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. | |
| Modificada | Alta (7.1) | 0.16% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected… | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. | |
| Modificada | Media (5.5) | 0.17% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Media (5.5) | 0.13% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Alta (7.8) | 0.23% | — | Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+1 | 11/2/2023 | 17/6/2026 | Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may… | |
| Modificada | Media (6.5) | 0.52% | — | Dell Supportassist FOR Home PCS | 10/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Media (5.9) | 0.95% | — | Bticino Door Entry FOR Hometouch | 6/2/2023 | 17/6/2026 | BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate. |