Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.14%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+1407/11/202317/6/2026
Information Disclosure in WLAN Host when processing WMI event command.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2677/11/202317/6/2026
Memory Corruption in Core due to secure memory access by user while loading modem image.
ModificadaCrítica (9.8)0.54%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+1723/10/202317/6/2026
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
ModificadaAlta (7.5)0.39%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3243/10/202317/6/2026
Transient DOS in WLAN Firmware while parsing rsn ies.
ModificadaAlta (7.5)0.39%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+1913/10/202317/6/2026
Transient DOS in WLAN Firmware while parsing a NAN management frame.
ModificadaAlta (7.8)0.12%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+1533/10/202317/6/2026
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
ModificadaMedia (6.5)0.70%—Netgear R6020 FirmwareNetgear R6080 FirmwareNetgear R6120 FirmwareNetgear R6220 Firmware+713/10/202017/6/2026
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd…
ModificadaMedia (5.5)0.54%—Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+69015/6/202017/6/2026
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.5)1.8%—Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+29613/3/202017/6/2026
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.
ModificadaAlta (8.8)3.1%—Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+29613/3/202017/6/2026
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)3.8%—Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+29613/3/202017/6/2026
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.
ModificadaMedia (5.6)1.1%💥 PoCIntel Atom C2308Intel Atom C2316Intel Atom C2338Intel Atom C2350+131712/3/202017/6/2026
Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334:…
ModificadaMedia (5.6)0.33%—Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+74812/3/202017/6/2026
Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. The list of affected products is provided in intel-sa-00330: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00330.html
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaMedia (5.3)1.8%—Honeywell Hbd3pr2 FirmwareHoneywell H4d3prv3 FirmwareHoneywell Hed3pr3 FirmwareHoneywell H4d3prv2 Firmware+5526/9/201917/6/2026
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance…
ModificadaAlta (8.8)2.4%—Tp-link Tl-er5510gTp-link Tl-er5520gTp-link Tl-er6120gTp-link Tl-er6520g+5127/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
ModificadaMedia (6.5)1.9%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the…
ModificadaAlta (8.8)2.9%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
ModificadaAlta (8.8)5.6%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.
ModificadaAlta (8.3)2.3%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1300-65Cisco Telepresence System 3000+1022/1/201417/6/2026
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC…
ModificadaAlta (10)2.1%—Cisco Telepresence System Tx9000Cisco Telepresence System Tx9200Cisco Telepresence System SoftwareCisco Telepresence System 1300+78/8/201316/6/2026
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug…
ModificadaAlta (9)2.2%—Cisco Telepresence System SoftwareCisco Telepresence System 1300 65Cisco Telepresence System 3000Cisco Telepresence System 3010+712/7/201216/6/2026
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
ModificadaAlta (8.3)1.2%—Cisco Telepresence System SoftwareCisco Telepresence System 1300 65Cisco Telepresence System 3000Cisco Telepresence System 3010+712/7/201216/6/2026
An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.
ModificadaAlta (7.8)1.8%—Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+1112/7/201216/6/2026
The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP…
ModificadaAlta (8.3)1.7%—Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+1112/7/201216/6/2026
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by…