Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.4)0.36%—Toshiba Password Tool FOR Windows20/4/202017/6/2026
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS,…
ModificadaAlta (8.8)3.4%—Toshiba Configfree23/1/202016/6/2026
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
ModificadaAlta (7.8)2.2%—Toshiba Configfree Utility27/12/201916/6/2026
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
ModificadaAlta (8.8)0.60%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.
ModificadaAlta (8.8)0.65%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.
ModificadaMedia (6.1)0.79%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.47%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device.
ModificadaMedia (6.5)0.50%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to bypass access restriction to access the information and files stored on the affected device.
ModificadaAlta (8.8)0.77%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.8)2.0%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ModificadaCrítica (9.8)1.4%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges.
ModificadaCrítica (9.8)1.5%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors.
ModificadaCrítica (9.8)1.8%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges.
ModificadaMedia (4.3)0.61%—Toshiba Flashair22/5/201717/6/2026
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
ModificadaBaja (3.5)0.45%—Toshiba Flashair22/5/201717/6/2026
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
ModificadaMedia (4.3)0.71%—Toshiba Flashair22/5/201717/6/2026
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02…
ModificadaAlta (8.8)3.0%—Toshiba Flashair28/4/201717/6/2026
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless…
ModificadaMedia (5.9)1.1%—Toshiba Coordinate Plus21/4/201717/6/2026
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
ModificadaBaja (3.7)1.7%—Toshiba 4690 Operating System31/12/201517/6/2026
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
ModificadaMedia (5)2.1%—Toshiba Chec24/6/201517/6/2026
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
ModificadaMedia (6.9)0.38%—Toshiba Bluetooth StackToshiba Service Station28/2/201517/6/2026
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
ModificadaBaja (3)0.28%—Toshibacommerce 4690 Point OF Sale Operating System21/4/201417/6/2026
The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file.
ModificadaMedia (6.8)1.1%💥 ExploitToshibatec E-studio-232Toshibatec E-studio-233Toshibatec E-studio-282Toshibatec E-studio-28319/4/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.
ModificadaAlta (10)4.7%💥 ExploitToshibatec E-studio-167 With Network Printer KIT FirmwareToshibatec E-studio-181 With Network Printer KIT FirmwareToshibatec E-studio-182 With Network Printer KIT FirmwareToshibatec E-studio-207 With Network Printer KIT Firmware+606/4/201216/6/2026
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.
ModificadaMedia (6.9)0.36%—Toshiba Face Recognition20/2/200916/6/2026
Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.
Orbitaley — Vulnerabilidades