Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.36% | — | Toshiba Password Tool FOR Windows | 20/4/2020 | 17/6/2026 | An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS,… | |
| Modificada | Alta (8.8) | 3.4% | — | Toshiba Configfree | 23/1/2020 | 16/6/2026 | Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Toshiba Configfree Utility | 27/12/2019 | 16/6/2026 | Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.60% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.65% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands. | |
| Modificada | Media (6.1) | 0.79% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.47% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device. | |
| Modificada | Media (6.5) | 0.50% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to bypass access restriction to access the information and files stored on the affected device. | |
| Modificada | Alta (8.8) | 0.77% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.0% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.4% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges. | |
| Modificada | Crítica (9.8) | 1.5% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.8% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges. | |
| Modificada | Media (4.3) | 0.61% | — | Toshiba Flashair | 22/5/2017 | 17/6/2026 | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser. | |
| Modificada | Baja (3.5) | 0.45% | — | Toshiba Flashair | 22/5/2017 | 17/6/2026 | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors. | |
| Modificada | Media (4.3) | 0.71% | — | Toshiba Flashair | 22/5/2017 | 17/6/2026 | The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02… | |
| Modificada | Alta (8.8) | 3.0% | — | Toshiba Flashair | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless… | |
| Modificada | Media (5.9) | 1.1% | — | Toshiba Coordinate Plus | 21/4/2017 | 17/6/2026 | Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates. | |
| Modificada | Baja (3.7) | 1.7% | — | Toshiba 4690 Operating System | 31/12/2015 | 17/6/2026 | Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138. | |
| Modificada | Media (5) | 2.1% | — | Toshiba Chec | 24/6/2015 | 17/6/2026 | CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access. | |
| Modificada | Media (6.9) | 0.38% | — | Toshiba Bluetooth StackToshiba Service Station | 28/2/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Baja (3) | 0.28% | — | Toshibacommerce 4690 Point OF Sale Operating System | 21/4/2014 | 17/6/2026 | The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Toshibatec E-studio-232Toshibatec E-studio-233Toshibatec E-studio-282Toshibatec E-studio-283 | 19/4/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords. | |
| Modificada | Alta (10) | 4.7% | 💥 Exploit | Toshibatec E-studio-167 With Network Printer KIT FirmwareToshibatec E-studio-181 With Network Printer KIT FirmwareToshibatec E-studio-182 With Network Printer KIT FirmwareToshibatec E-studio-207 With Network Printer KIT Firmware+60 | 6/4/2012 | 16/6/2026 | The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors. | |
| Modificada | Media (6.9) | 0.36% | — | Toshiba Face Recognition | 20/2/2009 | 16/6/2026 | Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user. |