Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3) | 0.28% | — | Toshibacommerce 4690 Point OF Sale Operating System | 21/4/2014 | 17/6/2026 | The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Toshibatec E-studio-232Toshibatec E-studio-233Toshibatec E-studio-282Toshibatec E-studio-283 | 19/4/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords. | |
| Modificada | Alta (10) | 4.7% | 💥 Exploit | Toshibatec E-studio-167 With Network Printer KIT FirmwareToshibatec E-studio-181 With Network Printer KIT FirmwareToshibatec E-studio-182 With Network Printer KIT FirmwareToshibatec E-studio-207 With Network Printer KIT Firmware+60 | 6/4/2012 | 16/6/2026 | The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors. | |
| Modificada | Media (6.9) | 0.36% | — | Toshiba Face Recognition | 20/2/2009 | 16/6/2026 | Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user. | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Toshiba Surveillix | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods. | |
| Modificada | Alta (10) | 2.3% | — | Toshiba Bluetooth | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Alta (10) | 1.4% | — | Toshiba Bluetooth Stack | 31/10/2006 | 16/6/2026 | Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405. | |
| Modificada | Media (6.2) | 0.38% | — | Toshiba Bluetooth Wireless Device Driver | 19/10/2006 | 16/6/2026 | Unspecified vulnerability in Toshiba Bluetooth wireless device driver 3.x and 4 through 4.00.35, as used in multiple products, allows physically proximate attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via crafted Bluetooth packets. | |
| Modificada | Media (5) | 2.5% | — | Toshiba Bluetooth Stack | 22/6/2006 | 16/6/2026 | The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrated by BlueSmack. NOTE: this issue was originally reported… | |
| Modificada | Media (5) | 2.5% | — | Toshiba Bluetooth Stack | 14/1/2006 | 16/6/2026 | Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push. | |
| Modificada | Baja (2.1) | 0.35% | — | Toshiba Acpi Flash Bios | 2/5/2005 | 16/6/2026 | An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,… | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. |