Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. | |
| Modificada | Alta (7.5) | 1.3% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks. | |
| Modificada | Alta (7.5) | 1.2% | — | Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+72 | 14/9/2020 | 17/6/2026 | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Shenzhen Hichip Vision Technology Firmware | 10/8/2020 | 17/6/2026 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products… | |
| Modificada | Alta (7.5) | 0.83% | — | Shenzhen Hichip Vision Technology Firmware | 10/8/2020 | 17/6/2026 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session data, as demonstrated by eavesdropping on user video/audio streams, capturing… | |
| Modificada | Crítica (9.8) | 2.9% | — | Shenzhen Hichip Vision Technology Firmware | 10/8/2020 | 17/6/2026 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code via the peer-to-peer… | |
| Modificada | Media (6.5) | 1.3% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php. | |
| Modificada | Media (6.5) | 1.1% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php. | |
| Modificada | Media (6.5) | 1.1% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php. | |
| Modificada | Media (6.5) | 1.1% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php. | |
| Modificada | Media (6.5) | 1.2% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php. | |
| Modificada | Media (6.1) | 0.67% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user). | |
| Modificada | Alta (7.5) | 0.91% | — | Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+1 | 17/2/2020 | 17/6/2026 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users. | |
| Modificada | Media (6.5) | 0.70% | — | Microchip Atmsamb11 Blusdk Smart | 10/2/2020 | 17/6/2026 | The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet. | |
| Modificada | Media (5.5) | 0.27% | — | Intel Chipset INF Utility | 17/1/2020 | 17/6/2026 | Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.7) | 0.47% | — | Microchip Atmel ToolboxAthena-scs IdprotectCryptsoft S/A Idflex VTecsec Armored Card+1 | 3/10/2019 | 17/6/2026 | Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue… | |
| Modificada | Alta (7.8) | 0.50% | — | Intel Chipset Device Software | 13/6/2019 | 17/6/2026 | Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access. | |
| Modificada | Media (6.8) | 0.43% | — | Chipsbank Umptool | 3/12/2018 | 17/6/2026 | ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device. | |
| Modificada | Crítica (9.6) | 4.6% | — | Debian LinuxOpenocd Open On-chip Debugger | 16/1/2018 | 17/6/2026 | Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site. | |
| Modificada | Crítica (9.8) | 64% | 💥 Exploit | Broadcom Bcm43xx Wi-fi Chipset Firmware | 4/6/2017 | 17/6/2026 | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. | |
| Modificada | Media (6.9) | 0.36% | — | Intel C202 ChipsetIntel C204 ChipsetIntel C206 ChipsetIntel C216 Chipset+6 | 12/9/2013 | 16/6/2026 | Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked,… | |
| Modificada | Alta (7.2) | 0.46% | — | Intel Sinit Authenticated Code ModuleIntel C202 ChipsetIntel C204 ChipsetIntel C206 Chipset+16 | 15/9/2012 | 16/6/2026 | Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before… | |
| Modificada | Media (4.3) | 1.0% | — | Bluechip BC Post2facebook | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Chipmunk-scripts Chipmunk Board | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Chipmunk-scripts Pwngame | 27/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to pwn.php. NOTE: some of these details are obtained from third party… |