Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)0.85%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.5)1.3%—H3C Magic B1st Firmware28/6/202317/6/2026
A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
ModificadaAlta (7.8)0.34%—Lenovo 100e 2ND GEN FirmwareLenovo 100w GEN 3 FirmwareLenovo 13W Yoga FirmwareLenovo 14W GEN 2 Firmware+6626/1/202317/6/2026
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
ModificadaCrítica (9.8)1.3%—Sick Sim2000st Firmware1/11/202217/6/2026
Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the…
ModificadaCrítica (9.8)1.3%—Sick Sim2000 FirmwareSick Sim2000st FirmwareSick Sim2500 FirmwareSick Sim1012 Firmware+31/11/202217/6/2026
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the…
ModificadaAlta (8.8)0.42%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+122/6/202217/6/2026
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product…
ModificadaMedia (6.7)2.8%💥 PoCLenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
ModificadaMedia (6.7)1.2%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+6922/4/202217/6/2026
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.
ModificadaMedia (6.7)1.3%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaAlta (7.4)0.80%—Moxa Mgate Mb3170i FirmwareMoxa Mgate Mb3170i-t FirmwareMoxa Mgate Mb3170-m-st FirmwareMoxa Mgate Mb3170-m-sc-t Firmware+1615/4/202217/6/2026
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate…
ModificadaAlta (8.8)0.45%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+1931/3/202217/6/2026
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware…
ModificadaMedia (5.5)0.23%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+2011/2/202217/6/2026
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health…
ModificadaAlta (8.8)0.99%—Phoenixcontact FL Switch 2005 FirmwarePhoenixcontact FL Switch 2008 FirmwarePhoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 Firmware+612/2/202217/6/2026
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
ModificadaAlta (8.8)0.52%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11…
ModificadaAlta (8)0.86%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11…
ModificadaMedia (4.3)0.38%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11…
ModificadaAlta (8.8)0.46%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware…
ModificadaAlta (8.8)0.55%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV…
ModificadaAlta (8)0.56%—Elecom Wrc-1167gst2 FirmwareElecom Wrc-1167gst2a FirmwareElecom Wrc-1167gst2h FirmwareElecom Wrc-2533gs2-b Firmware+101/12/202117/6/2026
ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware…
ModificadaAlta (8.8)0.82%—Netgear D8500 FirmwareNetgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900 Firmware+811/8/202117/6/2026
Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70,…
ModificadaMedia (4.8)0.51%—Netgear D3600 FirmwareNetgear D6000 FirmwareNetgear D6100 FirmwareNetgear D6200 Firmware+3911/8/202117/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 before 1.0.0.60, D6200 before 1.1.00.36, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before…
ModificadaBaja (2.7)0.77%—Netgear D3600 FirmwareNetgear D6000 FirmwareNetgear D6100 FirmwareNetgear D6200 Firmware+7011/8/202117/6/2026
Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.52, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A…
ModificadaMedia (6.7)0.35%—Intel Server Board S2600st FirmwareIntel Server Board S2600wf Firmware12/11/202017/6/2026
Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)1.0%—Netgear R6400v2 FirmwareNetgear R6400 FirmwareNetgear R7000p FirmwareNetgear Xr300 Firmware+99/11/202017/6/2026
upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overflow. This affects R6400v2 V1.0.4.102_10.0.75, R6400 V1.0.1.62_1.0.41, R7000P V1.3.2.126_10.1.66, XR300 V1.0.3.50_10.3.36, R8000 V1.0.4.62, R8300 V1.0.2.136, R8500 V1.0.2.136, R7300DST V1.0.0.74, R7850…