Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos Modem 5300 Firmware4/4/202317/6/2026
An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integer overflow in IPv4 fragment handling can occur due to insufficient parameter validation when reassembling these fragments.
ModificadaCrítica (9.8)23%—Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+123/3/202317/6/2026
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.
ModificadaCrítica (9.8)23%—Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+123/3/202317/6/2026
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.
ModificadaCrítica (9.8)23%—Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+121/3/202317/6/2026
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5125. Memory corruption can occur when processing Session Description Negotiation for Video Configuration Attribute.
ModificadaCrítica (9.8)0.93%—Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos Modem 5300 Firmware+113/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options.
ModificadaCrítica (9.8)1.1%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)1.0%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)1.1%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)33%—Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+113/3/202317/6/2026
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.
ModificadaCrítica (9.8)0.95%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+510/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)1.1%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1315/11/202217/6/2026
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.
ModificadaAlta (8.8)0.78%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1310/11/202217/6/2026
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user…
ModificadaMedia (5.4)0.46%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1310/11/202217/6/2026
Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage
ModificadaAlta (7.5)2.4%—Mediatek Modem9/9/202117/6/2026
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500736; Issue ID: ALPS04938456.
ModificadaAlta (7.5)2.4%—Mediatek Modem9/9/202117/6/2026
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964928.
ModificadaAlta (7.5)2.4%—Mediatek Modem9/9/202117/6/2026
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964926.
ModificadaAlta (7.5)2.4%—Mediatek Modem9/9/202117/6/2026
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964917.
ModificadaAlta (8.3)1.3%—Intel 2G Modem Firmware5/4/201817/6/2026
Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.
ModificadaCrítica (9.8)6.1%—Fiberhome Vdsl2 Modem HG 150-ub Firmware4/4/201817/6/2026
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
ModificadaCrítica (9.8)14%💥 ExploitFiberhome Vdsl2 Modem HG 150-ub Firmware4/4/201817/6/2026
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
ModificadaMedia (6.1)2.2%—Phoenixcontact FL Comserver Basic 232 FirmwarePhoenixcontact FL Comserver UNI 422 FirmwarePhoenixcontact FL Comserver BAS 485-t FirmwarePhoenixcontact FL COM Server Rs232 Firmware+911/12/201717/6/2026
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The…
ModificadaAlta (7.5)1.3%—Vivo Modem Firmware8/12/201717/6/2026
Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.
ModificadaCrítica (9.8)82%💥 ExploitEIR D1000 Modem Firmware16/5/201717/6/2026
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaCrítica (9.8)6.9%—Cisco Dpc2203 Cable Modem FirmwareCisco Epc2203 Cable Modem Firmware9/3/201617/6/2026
Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935.