Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)1.0%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again.
ModificadaMedia (4.3)0.64%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <…
ModificadaMedia (6.9)0.45%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),…
ModificadaMedia (6.9)0.69%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the device. This could allow an authenticated attacker with administrative privileges or an attacker that obtains a configuration backup to extract configuration information from the exported file.
ModificadaAlta (8.8)64%💥 PoCNetgate PfsenseNetgate Pfsense Plus14/11/202317/6/2026
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
ModificadaMedia (5.4)55%—Netgate Pfsense14/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
ModificadaMedia (5.4)58%—Netgate Pfsense14/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
ModificadaAlta (7.2)1.7%—Pfsense9/11/202317/6/2026
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
ModificadaCrítica (9.8)1.8%—Pfsense8/11/202317/6/2026
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2227/11/202317/6/2026
Cryptographic issue in HLOS during key management.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2677/11/202317/6/2026
Memory Corruption in Core due to secure memory access by user while loading modem image.
ModificadaMedia (6.5)0.45%—Dell Powerscale Onefs2/11/202317/6/2026
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
ModificadaMedia (6.5)0.62%—Dell Powerscale Onefs2/11/202317/6/2026
Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition.
ModificadaMedia (4.9)1.6%—Pfsense25/10/202317/6/2026
Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.
ModificadaAlta (7.8)0.35%—Lcdf Gifsicle18/10/202317/6/2026
gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
ModificadaMedia (5.9)0.47%—Oracle SUN ZFS Storage Appliance KIT17/10/202317/6/2026
Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability…
ModificadaMedia (5.5)0.31%—Lcdf Gifsicle9/10/202317/6/2026
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a…
ModificadaCrítica (9.8)1.7%—Fsevents Project Fsevents6/10/202317/6/2026
fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some…
ModificadaAlta (7.8)0.12%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1093/10/202317/6/2026
Memory Corruption in HLOS while registering for key provisioning notify.
ModificadaAlta (7.5)0.39%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2533/10/202317/6/2026
Transient DOS in Modem while allocating DSM items.
ModificadaAlta (7.8)0.60%—Apache Airflow Hdfs Provider14/9/202317/6/2026
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since…
ModificadaCrítica (9.8)1.4%—Dieboldnixdorf Agilis XFS FOR Opteva11/9/202317/6/2026
An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.
ModificadaMedia (6.8)25%—Zohocorp Manageengine Adselfservice Plus6/9/202317/6/2026
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this…
ModificadaAlta (7.8)0.12%—Qualcomm Aqt1000 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1265/9/202317/6/2026
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
ModificadaAlta (7.8)0.12%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fsm10056 FirmwareQualcomm Ipq5010 Firmware+1335/9/202317/6/2026
Memory Corruption in Core Platform while printing the response buffer in log.