Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.61% | — | Elecom Wrc-2533gst2 FirmwareElecom Wrc-1900gst2 FirmwareElecom Wrc-1750gst2 FirmwareElecom Wrc-1167gst2 Firmware | 6/10/2020 | 17/6/2026 | ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware versions prior to v1.14, and WRC-1167GST2 firmware versions prior to v1.10) allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via… | |
| Modificada | Crítica (9.8) | 2.3% | — | Mitsubishielectric Qj71mes96 FirmwareMitsubishielectric Qj71ws96 FirmwareMitsubishielectric Q06ccpu-v FirmwareMitsubishielectric Q24dhccpu-v Firmware+91 | 5/10/2020 | 17/6/2026 | Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands. | |
| Modificada | Alta (7.8) | 0.41% | — | Thomsonstb Tht741fta FirmwarePhilips Dtr3502bfta Dvb-t2 Firmware | 31/8/2020 | 17/6/2026 | THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol. | |
| Modificada | Media (5.9) | 0.42% | — | Thomsonstb Tht741fta FirmwarePhilips Dtr3502bfta Dvb-t2 Firmware | 31/8/2020 | 17/6/2026 | The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client. | |
| Modificada | Alta (8.2) | 0.34% | — | Intel S2600cw2 FirmwareIntel S2600cw2s FirmwareIntel S2600cwt FirmwareIntel S2600cwts Firmware+19 | 13/8/2020 | 17/6/2026 | Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.1) | 0.28% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.29% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Alta (7.8) | 0.33% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+4 | 14/11/2019 | 17/6/2026 | Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.27% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.27% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Alta (8.2) | 0.33% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.56% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access. | |
| Modificada | Media (6.7) | 0.32% | — | Intel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 FirmwareIntel Ethernet Controller Xxv710-am1 Firmware+3 | 14/11/2019 | 17/6/2026 | Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.28% | — | Phoenixcontact Mguard Centerport FirmwarePhoenixcontact Mguard Delta Tx/tx FirmwarePhoenixcontact Mguard Delta Tx/tx VPN FirmwarePhoenixcontact Mguard Gt/gt Firmware+19 | 30/1/2018 | 17/6/2026 | An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify… | |
| Modificada | Alta (7.5) | 28% | 💥 Exploit | Hbgk Hb7024xt FirmwareHbgk Hb7032xt FirmwareHbgk Hb7008t2 FirmwareHbgk Hb7016t2 Firmware+65 | 12/9/2017 | 17/6/2026 | On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change. |