Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.16% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (6.5) | 1.3% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (6.7) | 0.64% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Media (6.8) | 0.42% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.8) | 0.73% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (8.8) | 0.70% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.77% | — | Samsung Smartthings | 11/3/2025 | 17/6/2026 | Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Aplazada | Media (5.3) | 0.44% | — | Mennekes Smart ChargingpointAIMennekes Premium ChargingpointAI | 11/3/2025 | 17/6/2026 | Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized. | |
| Aplazada | Alta (7.1) | 0.42% | — | Mennekes Smart ChargingpointAIMennekes Premium ChargingpointAI | 11/3/2025 | 17/6/2026 | The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from the underlying OS. | |
| Aplazada | Alta (8.7) | 0.65% | — | Mennekes Smart Chargingpoint FirmwareAIMennekes Premium Chargingpoint FirmwareAI | 11/3/2025 | 17/6/2026 | The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain fields are passed to the underlying OS. | |
| Aplazada | Alta (8.7) | 0.65% | — | Mennekes Smart Charging Point FirmwareAIMennekes Premium Charging Point FirmwareAI | 11/3/2025 | 17/6/2026 | The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. | |
| Aplazada | Alta (8.7) | 0.65% | — | Mennekes Smart Chargingpoint FirmwareAIMennekes Premium Chargingpoint FirmwareAI | 11/3/2025 | 17/6/2026 | The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. | |
| Aplazada | Media (5.1) | 0.15% | — | Tinxy Smart DevicesAI | 11/3/2025 | 17/6/2026 | This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device. | |
| Aplazada | Alta (8.4) | 0.21% | — | Siemens Simatic Field PG M5AISiemens Simatic Field PG M6AISiemens Simatic IPC Bx-21aAISiemens Simatic IPC Bx-32aAI+28 | 11/3/2025 | 8/9/2026 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC… | |
| Aplazada | Alta (8.4) | 0.21% | — | Siemens Simatic Field PG M5AISiemens Simatic IPC Bx-21aAISiemens Simatic IPC Bx-32aAISiemens Simatic IPC Bx-39aAI+27 | 11/3/2025 | 8/9/2026 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC… | |
| Aplazada | Media (5.9) | 0.22% | — | Smartwares Cip-37210atAISmartwares C724ipAI | 6/3/2025 | 17/6/2026 | Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to path traversal. When an affected device is connected to a mobile app, it opens a port 10000 enabling a user to download pictures shot at specific moments by providing paths to the… | |
| Aplazada | Alta (7.5) | 0.16% | — | Smartwares Cip-37210atAISmartwares C724ipAI | 6/3/2025 | 17/6/2026 | Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory. For the telnet service to be enabled, the inserted SD card needs to… | |
| Aplazada | Alta (7.7) | 0.66% | — | Smartwares Cip-37210atAISmartwares C724ipAI | 6/3/2025 | 17/6/2026 | Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. During the initialization process, a user has to use a mobile app to provide devices with Access Point credentials. This input is not properly sanitized, what allows… | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+235 | 3/3/2025 | 17/6/2026 | Memory corruption while calling the NPU driver APIs concurrently. | |
| Analizada | Alta (7.5) | 0.30% | 💥 PoC | Qualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc2073 FirmwareQualcomm Qcc2076 Firmware+208 | 3/3/2025 | 17/6/2026 | Transient DOS may occur while processing the country IE. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Qcs6490 FirmwareQualcomm Qcs7230 FirmwareQualcomm Qcs8250 FirmwareQualcomm Qcs8300 Firmware+162 | 3/3/2025 | 17/6/2026 | Memory corruption in display driver while detaching a device. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Sm6370 FirmwareQualcomm Sm6650 FirmwareQualcomm Sm7250p FirmwareQualcomm Sm7315 Firmware+247 | 3/3/2025 | 17/6/2026 | Memory corruption may occur while validating ports and channels in Audio driver. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm C-v2x 9150 Firmware+240 | 3/3/2025 | 17/6/2026 | Information disclosure while deriving keys for a session for any Widevine use case. | |
| Analizada | Media (5.3) | 0.27% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+160 | 3/3/2025 | 17/6/2026 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. |