Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 1.0% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again. | |
| Modificada | Media (4.3) | 0.64% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <… | |
| Modificada | Media (6.9) | 0.45% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),… | |
| Modificada | Media (6.9) | 0.69% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the device. This could allow an authenticated attacker with administrative privileges or an attacker that obtains a configuration backup to extract configuration information from the exported file. | |
| Modificada | Alta (8.8) | 64% | 💥 PoC | Netgate PfsenseNetgate Pfsense Plus | 14/11/2023 | 17/6/2026 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | |
| Modificada | Media (5.4) | 55% | — | Netgate Pfsense | 14/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | |
| Modificada | Media (5.4) | 58% | — | Netgate Pfsense | 14/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | |
| Modificada | Alta (7.2) | 1.7% | — | Pfsense | 9/11/2023 | 17/6/2026 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pfsense | 8/11/2023 | 17/6/2026 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+222 | 7/11/2023 | 17/6/2026 | Cryptographic issue in HLOS during key management. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 7/11/2023 | 17/6/2026 | Memory Corruption in Core due to secure memory access by user while loading modem image. | |
| Modificada | Media (6.5) | 0.45% | — | Dell Powerscale Onefs | 2/11/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | |
| Modificada | Media (6.5) | 0.62% | — | Dell Powerscale Onefs | 2/11/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. | |
| Modificada | Media (4.9) | 1.6% | — | Pfsense | 25/10/2023 | 17/6/2026 | Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall. | |
| Modificada | Alta (7.8) | 0.35% | — | Lcdf Gifsicle | 18/10/2023 | 17/6/2026 | gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c. | |
| Modificada | Media (5.9) | 0.47% | — | Oracle SUN ZFS Storage Appliance KIT | 17/10/2023 | 17/6/2026 | Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability… | |
| Modificada | Media (5.5) | 0.31% | — | Lcdf Gifsicle | 9/10/2023 | 17/6/2026 | Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a… | |
| Modificada | Crítica (9.8) | 1.7% | — | Fsevents Project Fsevents | 6/10/2023 | 17/6/2026 | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+109 | 3/10/2023 | 17/6/2026 | Memory Corruption in HLOS while registering for key provisioning notify. | |
| Modificada | Alta (7.5) | 0.39% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+253 | 3/10/2023 | 17/6/2026 | Transient DOS in Modem while allocating DSM items. | |
| Modificada | Alta (7.8) | 0.60% | — | Apache Airflow Hdfs Provider | 14/9/2023 | 17/6/2026 | In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since… | |
| Modificada | Crítica (9.8) | 1.4% | — | Dieboldnixdorf Agilis XFS FOR Opteva | 11/9/2023 | 17/6/2026 | An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter. | |
| Modificada | Media (6.8) | 25% | — | Zohocorp Manageengine Adselfservice Plus | 6/9/2023 | 17/6/2026 | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+126 | 5/9/2023 | 17/6/2026 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fsm10056 FirmwareQualcomm Ipq5010 Firmware+133 | 5/9/2023 | 17/6/2026 | Memory Corruption in Core Platform while printing the response buffer in log. |