Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
ModificadaAlta (7.5)1.3%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
ModificadaCrítica (9.8)3.0%💥 PoCShenzhen Hichip Vision Technology Firmware10/8/202017/6/2026
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products…
ModificadaAlta (7.5)0.83%—Shenzhen Hichip Vision Technology Firmware10/8/202017/6/2026
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session data, as demonstrated by eavesdropping on user video/audio streams, capturing…
ModificadaCrítica (9.8)2.9%—Shenzhen Hichip Vision Technology Firmware10/8/202017/6/2026
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code via the peer-to-peer…
ModificadaMedia (6.5)1.3%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
ModificadaMedia (6.5)1.2%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
ModificadaMedia (6.1)0.67%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
ModificadaAlta (7.5)0.91%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
ModificadaMedia (6.5)0.70%—Microchip Atmsamb11 Blusdk Smart10/2/202017/6/2026
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
ModificadaMedia (5.5)0.27%—Intel Chipset INF Utility17/1/202017/6/2026
Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.7)0.47%—Microchip Atmel ToolboxAthena-scs IdprotectCryptsoft S/A Idflex VTecsec Armored Card+13/10/201917/6/2026
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue…
ModificadaAlta (7.8)0.50%—Intel Chipset Device Software13/6/201917/6/2026
Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.
ModificadaMedia (6.8)0.43%—Chipsbank Umptool3/12/201817/6/2026
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.
ModificadaCrítica (9.6)4.6%—Debian LinuxOpenocd Open On-chip Debugger16/1/201817/6/2026
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.
ModificadaCrítica (9.8)64%💥 ExploitBroadcom Bcm43xx Wi-fi Chipset Firmware4/6/201717/6/2026
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
ModificadaMedia (6.9)0.36%—Intel C202 ChipsetIntel C204 ChipsetIntel C206 ChipsetIntel C216 Chipset+612/9/201316/6/2026
Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked,…
ModificadaAlta (7.2)0.46%—Intel Sinit Authenticated Code ModuleIntel C202 ChipsetIntel C204 ChipsetIntel C206 Chipset+1615/9/201216/6/2026
Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before…
ModificadaMedia (4.3)1.0%—Bluechip BC Post2facebook14/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.0%💥 ExploitChipmunk-scripts Chipmunk Board5/10/201116/6/2026
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter.
ModificadaMedia (6.8)1.1%💥 ExploitChipmunk-scripts Pwngame27/4/201116/6/2026
Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to pwn.php. NOTE: some of these details are obtained from third party…
Orbitaley — Vulnerabilidades