Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.74%—Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+118/5/202217/6/2026
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
ModificadaCrítica (9.8)9.0%—LG N1t1 Firmware24/8/202117/6/2026
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
ModificadaMedia (4.3)0.29%—Hamilton-medical Hamilton-t1 Firmware15/3/202117/6/2026
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.
ModificadaMedia (4.3)0.26%—Hamilton-medical Hamilton-t1 Firmware15/3/202117/6/2026
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the device persistently unusable by uploading specially crafted configuration files.
ModificadaMedia (5.2)0.28%—Hamilton-medical Hamilton-t1 Firmware15/3/202117/6/2026
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers with physical access to obtain admin privileges for the device’s configuration interface.
ModificadaMedia (6.5)8.9%💥 ExploitDlink Dir-615 T1 Firmware16/12/201917/6/2026
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
ModificadaCrítica (9.8)1.8%—Zyxel P-660hn-t1 Firmware31/5/201917/6/2026
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
ModificadaMedia (4.8)3.4%💥 ExploitD-link Dir-615 T1 Firmware18/4/201817/6/2026
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
ModificadaMedia (5.9)1.4%—Oleumtech FT1 FirmwareOleumtech AD1 Firmware6/4/201817/6/2026
OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading cleartext protocol data.
ModificadaCrítica (9.8)3.8%—Mitrastar Gpt-2541gnac FirmwareMitrastar Dsl-100hn-t1 Firmware3/11/201717/6/2026
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented.
ModificadaAlta (8.8)2.6%—Mitrastar Gpt-2541gnac FirmwareMitrastar Dsl-100hn-t1 Firmware3/11/201717/6/2026
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying /bin/sh as the command to execute.
ModificadaAlta (7.5)0.89%—Zyxel P-663hn-51 FirmwareZyxel P-660h-61 FirmwareZyxel P-660h-63 FirmwareZyxel P-660h-67 Firmware+1526/3/200816/6/2026
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.