Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.31%—Marvell 88ss1074 FirmwareMarvell 88ss1079 FirmwareMarvell 88ss1080 FirmwareMarvell 88ss1093 Firmware+155/6/201917/6/2026
Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices are vulnerable in manipulating a combination of IO pins to bypass the secure boot protection…
ModificadaMedia (4.6)0.35%—Marvell 88ss1074 FirmwareMarvell 88ss1079 FirmwareMarvell 88ss1080 FirmwareMarvell 88ss1093 Firmware+154/6/201917/6/2026
Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices allow reprogramming flash memory to bypass the secure boot protection mechanism.
ModificadaMedia (6.1)3.1%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Compactlogix 5370 L1 Firmware+225/4/201917/6/2026
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix…
ModificadaMedia (6.1)21%💥 ExploitZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp800 FirmwareZyxel Usg20-vpn Firmware+1722/4/201917/6/2026
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
ModificadaAlta (7.5)2.1%—Verizon Fios Quantum Gateway G1100 Firmware11/4/201917/6/2026
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. /api).
ModificadaAlta (7.5)0.64%—Verizon Fios Quantum Gateway G1100 Firmware11/4/201917/6/2026
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.
ModificadaAlta (7.2)30%—Verizon Fios Quantum Gateway G1100 Firmware11/4/201917/6/2026
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.
ModificadaMedia (5.9)0.97%—Zyxel Zywall 110 FirmwareZyxel Zywall 1100 FirmwareZyxel Zywall 310 FirmwareZyxel Zywall VPN 50 Firmware+1315/8/201817/6/2026
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
ModificadaAlta (8.1)1.2%—Dlink Dgs-1100 Firmware9/1/201717/6/2026
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
ModificadaAlta (7.5)4.5%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request.
ModificadaMedia (4)1.6%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticated users to insert the content of an arbitrary file into a FRAME element via unspecified vectors.
ModificadaCrítica (9.8)7.0%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)2.8%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)4.3%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.4)3.2%💥 ExploitHPE Compaq Wl310 FirmwareProxim Orinoco Rg-1000 FirmwareProxim Orinoco Rg-1100 Firmware12/8/200216/6/2026
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.