Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.23%—Siemens Scalance W1748-1AISiemens Scalance W1788-1AISiemens Scalance W1788-2AISiemens Scalance W1788-2iaAI+179/4/202417/6/2026
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1…
AplazadaMedia (6.1)0.20%—Siemens Scalance WAI9/4/202417/6/2026
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1…
AplazadaMedia (6.1)0.21%—Siemens Scalance W721-1AISiemens Scalance W722-1AISiemens Scalance W734-1AISiemens Scalance W738-1AI+99/4/202417/6/2026
A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0) (All…
AnalizadaCrítica (9.8)0.69%—Scalapay25/3/202417/6/2026
SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.
AnalizadaMedia (5.4)0.37%—Sterlinghamilton Scalable Vector Graphics (svg)18/3/202417/6/2026
The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaAlta (8.6)0.38%—Siemens Scalance Xb208 (e/ip) FirmwareSiemens Scalance Xb208 (pn) FirmwareSiemens Scalance Xb216 (e/ip) FirmwareSiemens Scalance Xb216 (pn) Firmware+6514/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <…
ModificadaAlta (7.1)0.34%—Scala-sbt IOScala-sbt SBT23/10/202317/6/2026
sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwrite `/root/.ssh/authorized_keys`. Within sbt's main code, `IO.unzip` is used in `pullRemoteCache` task and `Resolvers.remote`; however many…
ModificadaBaja (2.7)0.56%—Siemens Scalance Lpe9403 Firmware9/5/202317/6/2026
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a…
ModificadaBaja (3.3)0.17%—Siemens Scalance Lpe9403 Firmware9/5/202317/6/2026
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.
ModificadaBaja (3.3)0.17%—Siemens Scalance Lpe9403 Firmware9/5/202317/6/2026
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an authenticated attacker with access to the SSH interface on the…
ModificadaCrítica (9.9)1.3%—Siemens Scalance Lpe9403 Firmware9/5/202317/6/2026
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.
ModificadaAlta (7.4)0.26%—Siemens Scalance X200-4p IRT FirmwareSiemens Scalance X201-3p IRT FirmwareSiemens Scalance X201-3p IRT PRO FirmwareSiemens Scalance X202-2irt Firmware+911/4/202317/6/2026
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2),…
ModificadaMedia (5.1)0.72%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
ModificadaMedia (5.2)0.27%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
ModificadaAlta (7.1)0.24%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
ModificadaMedia (6.1)0.47%—Siemens Scalance X200-4p IRT FirmwareSiemens Scalance X201-3p IRT FirmwareSiemens Scalance X201-3p IRT PRO FirmwareSiemens Scalance X202-2irt Firmware+2611/10/202217/6/2026
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT PRO (All versions < V5.5.0), SCALANCE X202-2IRT (All versions < V5.5.0), SCALANCE X202-2P IRT (All versions < V5.5.0), SCALANCE X202-2P IRT PRO (All versions <…
AnalizadaAlta (8.6)1.1%—Siemens Ruggedcom Rm1224 FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 FirmwareSiemens Scalance M816-1 Firmware+1211/10/202217/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.1.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <…
ModificadaMedia (6.1)0.67%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of…
ModificadaMedia (4.9)0.85%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below;…
ModificadaMedia (6.5)0.46%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below;…
ModificadaAlta (7.8)0.73%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and…
ModificadaMedia (5.4)0.71%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the…
ModificadaCrítica (9.8)1.4%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and…
ModificadaCrítica (9.8)1.4%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and…
ModificadaCrítica (9.8)2.1%—Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware7/10/202217/6/2026
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability…