Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.39%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required…
AnalizadaMedia (6.3)0.27%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit…
AnalizadaAlta (7.5)0.28%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a…
AnalizadaAlta (7.5)0.17%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain the ability to pair a malicious…
AnalizadaMedia (6.5)0.55%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is required to exploit this…
AnalizadaAlta (8.8)0.41%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged…
AplazadaAlta (8.7)0.17%—Nvidia Connectx Host FirmwareAINvidia Bluefield DPUAI1/11/202417/6/2026
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.
ModificadaCrítica (9.8)0.56%—H3C Magic B1st Firmware16/8/202417/6/2026
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
AnalizadaAlta (7.1)0.18%—Intel Server Board S2600st Firmware14/8/202417/6/2026
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (10)0.24%—Google Chromecast Firmware5/4/202417/6/2026
u-boot bug that allows for u-boot shell and interrupt over UART
ModificadaCrítica (9.8)0.37%—Google Chromecast Firmware11/12/202317/6/2026
An oversight in BCB handling of reboot reason that allows for persistent code execution
ModificadaCrítica (9.8)0.37%—Google Chromecast Firmware11/12/202317/6/2026
U-Boot vulnerability resulting in persistent Code Execution
ModificadaCrítica (9.8)0.32%—Google Chromecast Firmware11/12/202317/6/2026
U-Boot shell vulnerability resulting in Privilege escalation in a production device
ModificadaCrítica (9.8)0.30%—Google Chromecast Firmware11/12/202317/6/2026
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
ModificadaAlta (8.8)0.31%—Moxa Nport 5150ai-m12-ct-t FirmwareMoxa Nport 5250ai-m12-ct-t FirmwareMoxa Nport 5150ai-m12-t FirmwareMoxa Nport 5250ai-m12-t Firmware+1043/10/202317/6/2026
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.
ModificadaAlta (8.8)0.28%—Furunosystems Acera 1210 FirmwareFurunosystems Acera 1150i FirmwareFurunosystems Acera 1150w FirmwareFurunosystems Acera 1110 Firmware+83/10/202317/6/2026
Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35…
ModificadaMedia (5.4)0.35%—Furunosystems Acera 1210 FirmwareFurunosystems Acera 1150i FirmwareFurunosystems Acera 1150w FirmwareFurunosystems Acera 1110 Firmware+83/10/202317/6/2026
Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA…
ModificadaAlta (8.8)1.5%—Furunosystems Acera 1310 FirmwareFurunosystems Acera 1320 FirmwareFurunosystems Acera 1210 FirmwareFurunosystems Acera 1150i Firmware+103/10/202317/6/2026
OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and versions are as follows: ACERA 1320 firmware…
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.