Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.94%—Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+21211/7/202317/6/2026
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information…
ModificadaAlta (7.8)0.35%—Toshiba Storage Security Software31/1/202317/6/2026
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
ModificadaAlta (8.3)1.6%—Shiba Project Shiba2/10/202017/6/2026
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().
ModificadaAlta (8.4)0.36%—Toshiba Password Tool FOR Windows20/4/202017/6/2026
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS,…
ModificadaAlta (8.8)3.4%—Toshiba Configfree23/1/202016/6/2026
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
ModificadaAlta (7.8)2.2%—Toshiba Configfree Utility27/12/201916/6/2026
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
ModificadaAlta (8.8)0.60%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.
ModificadaAlta (8.8)0.65%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.
ModificadaMedia (6.1)0.79%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.47%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device.
ModificadaMedia (6.5)0.50%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to bypass access restriction to access the information and files stored on the affected device.
ModificadaMedia (6.1)1.1%—Shiba Project Shiba3/1/201817/6/2026
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
ModificadaAlta (8.8)0.77%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.8)2.0%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ModificadaCrítica (9.8)1.4%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges.
ModificadaCrítica (9.8)1.5%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors.
ModificadaCrítica (9.8)1.8%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges.
ModificadaMedia (4.3)0.61%—Toshiba Flashair22/5/201717/6/2026
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
ModificadaBaja (3.5)0.45%—Toshiba Flashair22/5/201717/6/2026
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
ModificadaMedia (4.3)0.71%—Toshiba Flashair22/5/201717/6/2026
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02…
ModificadaAlta (8.8)3.0%—Toshiba Flashair28/4/201717/6/2026
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless…
ModificadaMedia (5.9)1.1%—Toshiba Coordinate Plus21/4/201717/6/2026
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
ModificadaBaja (3.7)1.7%—Toshiba 4690 Operating System31/12/201517/6/2026
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
ModificadaMedia (5)2.1%—Toshiba Chec24/6/201517/6/2026
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
ModificadaMedia (6.9)0.38%—Toshiba Bluetooth StackToshiba Service Station28/2/201517/6/2026
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
Orbitaley — Vulnerabilidades