Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.26% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Media (6.5) | 0.54% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering. | |
| Modificada | Media (4.9) | 0.56% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Semg9811 FirmwareHuawei Usg9500 Firmware | 22/6/2021 | 17/6/2026 | There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00,… | |
| Modificada | Media (6.5) | 0.58% | — | Huawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 FirmwareHuawei Secospace Usg6600 Firmware+1 | 27/5/2021 | 17/6/2026 | There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the… | |
| Modificada | Media (4.9) | 0.64% | — | Huawei Usg9500 Firmware | 27/5/2021 | 17/6/2026 | There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Zebra Fx9500 Firmware | 11/5/2021 | 17/6/2026 | An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code execution. NOTE: This vulnerability only… | |
| Modificada | Media (6.5) | 0.83% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+8 | 8/4/2021 | 17/6/2026 | There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions… | |
| Modificada | Media (5.3) | 0.71% | — | Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 FirmwareHuawei S12700 Firmware+10 | 22/3/2021 | 17/6/2026 | There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of… | |
| Modificada | Media (4.4) | 0.19% | — | Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 22/3/2021 | 17/6/2026 | There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions… | |
| Modificada | Alta (7.5) | 0.77% | — | Huawei Usg9500 FirmwareHuawei Usg9520 FirmwareHuawei Usg9560 FirmwareHuawei Usg9580 Firmware | 22/3/2021 | 17/6/2026 | There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200,… | |
| Modificada | Alta (7.5) | 0.73% | — | Huawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 Firmware+4 | 22/3/2021 | 17/6/2026 | There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600,… | |
| Modificada | Media (6.5) | 0.60% | — | Huawei Usg9500 Firmware | 22/3/2021 | 17/6/2026 | There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs in to device. The attacker can exploit the vulnerability to perform some operation and can get information and cause information leak. | |
| Modificada | Media (6.5) | 0.35% | — | Huawei Nip6800 FirmwareHuawei S12700 FirmwareHuawei S2700 FirmwareHuawei S5700 Firmware+5 | 13/1/2021 | 17/6/2026 | There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions… | |
| Modificada | Alta (7.5) | 1.2% | — | NEC Univerge Sv9500 FirmwareNEC Univerge Sv8500 Firmware | 13/1/2021 | 17/6/2026 | Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL. | |
| Modificada | Crítica (9.8) | 1.8% | — | NEC Univerge Sv9500 FirmwareNEC Univerge Sv8500 Firmware | 13/1/2021 | 17/6/2026 | UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL. | |
| Modificada | Media (6.5) | 0.32% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 24/12/2020 | 17/6/2026 | There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal. | |
| Modificada | Media (6.7) | 0.39% | — | Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 13/11/2020 | 17/6/2026 | Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions… | |
| Modificada | Alta (7.5) | 0.74% | — | Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 13/11/2020 | 17/6/2026 | There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific protocol. A remote, unauthorized attackers can construct attack scenarios, which leads to denial of service.Affected product versions include:NIP6300 versions… | |
| Modificada | Media (6.5) | 0.40% | — | Netgear Wc7500 FirmwareNetgear Wc7600 FirmwareNetgear Wc9500 Firmware | 9/10/2020 | 17/6/2026 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24. | |
| Modificada | Media (4.8) | 0.52% | — | Netgear Wc7500 FirmwareNetgear Wc7600 FirmwareNetgear Wc7600v2 FirmwareNetgear Wc9500 Firmware | 9/10/2020 | 17/6/2026 | Certain NETGEAR devices are affected by stored XSS. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24. | |
| Modificada | Media (6.7) | 0.44% | — | Netgear Wc7500 FirmwareNetgear Wc7600 FirmwareNetgear Wc7600v2 FirmwareNetgear Wc9500 Firmware | 9/10/2020 | 17/6/2026 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24. | |
| Modificada | Media (6.5) | 0.33% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 18/7/2020 | 17/6/2026 | There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include:… | |
| Modificada | Alta (7.5) | 0.88% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+46 | 8/7/2020 | 17/6/2026 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause… | |
| Modificada | Alta (7.5) | 0.88% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+46 | 8/7/2020 | 17/6/2026 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause… | |
| Modificada | Alta (7.5) | 0.88% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+46 | 8/7/2020 | 17/6/2026 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause… |