Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.14%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM.
ModificadaAlta (7.8)0.17%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
ModificadaMedia (6.1)8.5%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
ModificadaCrítica (9.8)65%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
ModificadaAlta (8.2)7.0%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
ModificadaMedia (6.8)0.37%—Dell Chengming 3980 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G3 3579 Firmware+1049/8/202217/6/2026
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
ModificadaMedia (6.2)0.15%—Stsafe-j FirmwareST J-safe3 Firmware4/3/202217/6/2026
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN…
ModificadaMedia (6.2)0.16%—ST J-safe3 FirmwareStsafe-j Firmware4/3/202217/6/2026
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed…
AnalizadaMedia (6.4)0.24%—Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+40724/1/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
AnalizadaMedia (6.4)0.25%—Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+40724/1/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitHikvision Ds-2cd2026g2-iu/sl FirmwareHikvision Ds-2cd2046g2-iu/sl FirmwareHikvision Ds-2cd2066g2-i(u) FirmwareHikvision Ds-2cd2066g2-iu/sl Firmware+25222/9/202117/6/2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaMedia (4.3)0.28%—Samsung S5 FirmwareSamsung Note3 FirmwareSamsung S4 FirmwareSamsung Note2 Firmware+17/4/202017/6/2026
An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).
ModificadaMedia (5.3)0.35%—Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+17021/2/202017/6/2026
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring…
ModificadaMedia (6.8)0.36%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+2375/8/201917/6/2026
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.…
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaCrítica (9.8)4.2%—Nortekcontrol Emerge E3 Firmware19/2/201817/6/2026
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.
ModificadaMedia (5.3)1.2%—Moxa Miineport E1 FirmwareMoxa Miineport E2 FirmwareMoxa Miineport E3 Firmware13/2/201717/6/2026
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are stored in a file that is not encrypted.
ModificadaAlta (7.5)1.6%—Moxa Miineport E1 FirmwareMoxa Miineport E2 FirmwareMoxa Miineport E3 Firmware13/2/201717/6/2026
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
ModificadaAlta (7.5)1.5%—Moxa Miineport E2 1242 FirmwareMoxa Miineport E1 4641 FirmwareMoxa Miineport E2 4561 FirmwareMoxa Miineport E3 Firmware+131/5/201617/6/2026
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allow…
ModificadaAlta (7.5)1.4%—Moxa Miineport E2 1242 FirmwareMoxa Miineport E1 7080 FirmwareMoxa Miineport E2 4561 FirmwareMoxa Miineport E3 Firmware+131/5/201617/6/2026
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a…
ModificadaAlta (8.8)0.59%—Moxa Miineport E2 1242 FirmwareMoxa Miineport E2 4561 FirmwareMoxa Miineport E1 7080 FirmwareMoxa Miineport E3 Firmware+131/5/201617/6/2026
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3…