Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.77% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8076 Firmware+467 | 21/1/2021 | 17/6/2026 | Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Alta (8.8) | 2.4% | — | Meinbergglobal Lantime M300 FirmwareMeinbergglobal Lantime M1000 Firmware | 20/1/2020 | 17/6/2026 | Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Configuration). Note: According to the description, the vulnerability requires a fully authenticated super-user account using… | |
| Modificada | Media (5.5) | 0.67% | — | HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Proliant Xl750f Gen9 Server Firmware+97 | 3/12/2018 | 17/6/2026 | The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the… | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | |
| Modificada | Alta (7.5) | 1.8% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | |
| Modificada | Alta (8.1) | 5.1% | 💥 Exploit | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to… | |
| Modificada | Alta (7.3) | 1.1% | — | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allow remote attackers to obtain… | |
| Modificada | Alta (7.3) | 5.2% | 💥 Exploit | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote attackers to obtain sensitive… | |
| Modificada | Baja (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 1/4/2015 | 17/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modificada | Media (4.3) | 1.8% | — | Meinberg NTP Server FirmwareMeinberg Lantime M100Meinberg Lantime M200Meinberg Lantime M300+4 | 5/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 4.2% | — | Juniper Network AND Security Manager SoftwareJuniper Nsm3000Juniper Nsmexpress | 19/5/2014 | 17/6/2026 | Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 1.6% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the SPARC Enterprise M Series Servers component in Oracle and Sun Systems Products Suite XCP 1114 and earlier allows remote attackers to affect availability via vectors related to XSCF Control Package (XCP). | |
| Modificada | Media (5.9) | 84% | — | Oracle Communications Application Session ControllerOracle Http ServerOracle Integrated Lights OUT Manager FirmwareFujitsu Sparc Enterprise M3000 Firmware+12 | 15/3/2013 | 16/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. | |
| Modificada | Baja (2.6) | 2.1% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 allows remote attackers to affect availability, related to XSCF Control Package (XCP). | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 and earlier allows local users to affect confidentiality, related to XSCF Control Package (XCP). | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M3000, M4000, M5000, M8000, and M9000 XCP 1101 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to XSCF Control Package (XCP). | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sterlitetechnologies Sam300 AX Router | 11/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter. |