Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.30% | — | Silabs 500 Series FirmwareDome Dm501Jasco Zw4201Linear Lb60z-1 | 10/1/2022 | 17/6/2026 | Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection. | |
| Modificada | Crítica (9.8) | 1.5% | — | Thunderdome Planning Poker | 2/11/2021 | 17/6/2026 | Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are… | |
| Modificada | Media (6.1) | 0.55% | — | HPE Superdome Flex FirmwareHPE Superdome Flex 280 Firmware | 19/10/2021 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex… | |
| Modificada | Media (4.3) | 0.36% | — | Kadenvodomery Picoflux AIR Firmware | 16/9/2021 | 17/6/2026 | In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties. | |
| Modificada | Media (6.5) | 0.84% | — | HPE Superdome Flex Server Firmware | 1/4/2021 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following… | |
| Modificada | Media (4.3) | 0.50% | — | Cisco Video Surveillance 8000p IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8070 IP Camera Firmware+4 | 13/1/2021 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker… | |
| Modificada | Alta (8.8) | 0.75% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute arbitrary code on an affected device or cause the device to reload. This vulnerability is due to missing checks when an IP camera processes a… | |
| Modificada | Media (6.5) | 0.45% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Alta (8.8) | 0.70% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Alta (8.8) | 0.95% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Media (6.5) | 0.57% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Media (6.7) | 0.30% | — | HPE Superdome Flex Server Firmware | 19/5/2020 | 17/6/2026 | A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Flex Server version 3.25.46 or later to resolve this issue. | |
| Modificada | Alta (8.8) | 5.7% | — | Cisco Video Surveillance 8400 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8000p IP Camera Firmware+4 | 5/2/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery… | |
| Modificada | Media (5.5) | 0.76% | — | HPE Superdome Flex Server Firmware | 16/1/2020 | 17/6/2026 | HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information disclosure, or denial of service. HPE has… | |
| Modificada | Crítica (9.8) | 3.5% | — | Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+2 | 23/5/2019 | 17/6/2026 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the… | |
| Modificada | Alta (7.5) | 1.8% | — | Pycryptodome | 20/8/2018 | 17/6/2026 | PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | |
| Modificada | Alta (7.5) | 1.8% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | |
| Modificada | Media (5.4) | 0.27% | — | Hdcar Exercitii Pentru Abdomen | 23/9/2014 | 17/6/2026 | The Exercitii pentru abdomen (aka com.rareartifact.exercitiipentruabdomen41E29322) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |