Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+1830/6/201717/6/2026
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow…
ModificadaAlta (7.8)3.9%—Trendmicro Endpoint Sensor10/3/201717/6/2026
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208.
ModificadaMedia (6.5)1.2%—Blackbox Alertwerks Servsensor Junior FirmwareBlackbox Alertwerks Servsensor Contact FirmwareBlackbox Alertwerks Servsensor Firmware30/5/201617/6/2026
Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact with firmware before SP473 allow remote authenticated users to discover administrator and user…
ModificadaMedia (6.1)0.91%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)2.1%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
ModificadaMedia (5.3)1.2%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
ModificadaAlta (8.8)0.60%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (7.1)1.2%—Cisco IPS Sensor Software21/2/201517/6/2026
Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections during the key-regeneration phase of an upgrade, aka Bug ID CSCui25688.
ModificadaAlta (7.8)1.6%—Oleumtech Sensor Wireless I/O ModuleOleumtech WIO DH2 Wireless Gateway24/7/201417/6/2026
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.
ModificadaAlta (7.2)0.40%—Oleumtech Sensor Wireless I/O ModuleOleumtech WIO DH2 Wireless Gateway24/7/201417/6/2026
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.
ModificadaAlta (7.5)3.4%—Oleumtech Sensor Wireless I/O ModuleOleumtech WIO DH2 Wireless Gateway24/7/201417/6/2026
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage.
ModificadaAlta (7.1)1.2%—Cisco IPS Sensor Software22/2/201417/6/2026
Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via a flood of jumbo frames, aka Bug ID CSCuh94944.
ModificadaAlta (7.8)1.6%—Cisco IPS Sensor Software22/2/201417/6/2026
The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (MainApp process outage) via crafted packets to TCP port 7000, aka Bug ID CSCui67394.
ModificadaAlta (7.1)1.7%—Cisco IPS Sensor Software22/2/201417/6/2026
The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via fragmented packets, aka Bug ID CSCui91266.
ModificadaAlta (7.8)1.3%—Cisco ASA 5500-x Series IPS SSP SoftwareCisco Intrusion Prevention SystemCisco ASA 5585-xCisco Idsm-2+518/7/201316/6/2026
The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID…
ModificadaAlta (7.8)1.9%—Cisco ASA 5500-x Series IPS SSP SoftwareCisco Intrusion Prevention SystemCisco ASA 5585-xCisco Idsm-2+518/7/201316/6/2026
Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.
ModificadaAlta (9)9.3%💥 ExploitSourcefire 3D SensorSourcefire Defense Center7/7/200916/6/2026
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.
ModificadaMedia (5)9.6%💥 ExploitAirdefense Airsensor24/9/200716/6/2026
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."
ModificadaAlta (7.8)3.0%—Cisco IPS Sensor SoftwareCisco IOS16/5/200716/6/2026
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
ModificadaAlta (10)79%💥 ExploitSnortSourcefire Intrusion Sensor20/2/200716/6/2026
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
ModificadaMedia (5)3.5%—Cisco IDS Sensor SoftwareCisco IPS Sensor Software21/9/200616/6/2026
The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.
ModificadaAlta (7.5)4.2%—Cisco IPS Sensor Software21/9/200616/6/2026
Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets".
ModificadaMedia (5)2.4%—ISS Blackice PC ProtectionISS Blackice Server ProtectionISS Proventia DesktopISS Realsecure Desktop+627/7/200616/6/2026
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is…
ModificadaMedia (5)1.8%—Cisco IPS Sensor Software18/7/200616/6/2026
The device driver for Intel-based gigabit network adapters in Cisco Intrusion Prevention System (IPS) 5.1(1) through 5.1(p1), as installed on various Cisco Intrusion Prevention System 42xx appliances, allows remote attackers to cause a denial of service (kernel panic and possibly network outage) via a crafted IP…
ModificadaBaja (2.1)0.42%—Ciscoworks Management Center FOR IPS Sensors2/11/200516/6/2026
The Cisco Management Center (MC) for IPS Sensors (IPS MC) 2.1 can omit port field values while generating the Cisco IOS IPS configuration file, wich can cause some signatures to be disabled and makes it easier for attackers to escape detection.
Orbitaley — Vulnerabilidades