Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.14% | — | HP 348 G4 FirmwareHP 260 G2 Desktop Mini FirmwareHP 218 PRO G5 MT FirmwareHP 260 G3 Desktop Mini Firmware+21 | 12/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Media (5.4) | 0.57% | — | Teradek Vidiu Mini FirmwareTeradek Vidiu Firmware | 3/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to… | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Alta (8.4) | 0.24% | — | HP Z1 G3 FirmwareHP Z2 Mini G3 FirmwareHP Z238 Microtower FirmwareHP Z240 SFF Firmware+71 | 12/12/2022 | 17/6/2026 | A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (4.6) | 0.59% | — | NXP I.mx 6 FirmwareNXP I.mx 6dual FirmwareNXP I.mx 6duallite FirmwareNXP I.mx 6dualplus Firmware+19 | 18/11/2022 | 17/6/2026 | An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled… | |
| Modificada | Crítica (9.9) | 0.82% | — | Carel Boss Mini Firmware | 18/11/2022 | 17/6/2026 | Carel Boss Mini 1.5.0 has Improper Access Control. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddWlanMacList. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddMacList. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function WlanWpsSet. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMobileAPInfoById. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMacAccessMode. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAP5GWifiById. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed. | |
| Modificada | Alta (7.8) | 0.36% | — | H3C B5 Mini Firmware | 25/8/2022 | 17/6/2026 | H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function EditMacList.d. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Media (6.5) | 2.9% | — | Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+190 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. | |
| Modificada | Media (5.3) | 6.5% | — | NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+162 | 11/5/2021 | 17/6/2026 | An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to… | |
| Modificada | Baja (3.5) | 3.6% | — | Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+177 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary… | |
| Modificada | Baja (2.6) | 2.6% | — | Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+164 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Asus Lyra Mini FirmwareAsus Gt-ac2900 Firmware | 6/5/2021 | 17/6/2026 | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in… |