Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.87%—Lexmark X860 FirmwareLexmark X862 FirmwareLexmark X864 FirmwareLexmark X734 Firmware+299/3/202016/6/2026
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
ModificadaMedia (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.53%—Lexmark Cx31x FirmwareLexmark Cx41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7613/2/202017/6/2026
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (5.3)1.8%—Honeywell Hbd3pr2 FirmwareHoneywell H4d3prv3 FirmwareHoneywell Hed3pr3 FirmwareHoneywell H4d3prv2 Firmware+5526/9/201917/6/2026
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance…
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
ModificadaAlta (7.5)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have an Integer Overflow.
ModificadaMedia (5.3)0.87%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
ModificadaCrítica (9.1)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7028/8/201917/6/2026
Various Lexmark products have Incorrect Access Control.
ModificadaCrítica (9.8)3.2%—Mediatek Mt8163 FirmwareMediatek Mt6625 FirmwareMediatek Mt6577 Firmware14/8/201917/6/2026
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in platform/mt6577/external/meta/emmc/meta_clr_emmc.c invokes…
ModificadaAlta (7.8)0.21%—Qualcomm Ipq4019 FirmwareQualcomm Ipq8064 FirmwareQualcomm Ipq8074 FirmwareQualcomm Mdm9206 Firmware+5224/5/201917/6/2026
Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired…
ModificadaAlta (7.8)0.22%—Qualcomm Fsm9055 FirmwareQualcomm Fsm9955 FirmwareQualcomm Ipq4019 FirmwareQualcomm Mdm9206 Firmware+356/5/201917/6/2026
Lack of check of buffer length before copying can lead to buffer overflow in camera module in Small Cell SoC, Snapdragon Mobile, Snapdragon Wear in FSM9055, FSM9955, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD…
ModificadaBaja (3.3)0.24%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+17310/4/201917/6/2026
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo…
ModificadaMedia (5.3)0.94%—Lexmark Xm5163 FirmwareLexmark Xm5170 FirmwareLexmark Xm7155 FirmwareLexmark Xm7163 Firmware+3611/2/201917/6/2026
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.
ModificadaAlta (7.8)0.23%—Qualcomm Ipq4019 FirmwareQualcomm Ipq8064 FirmwareQualcomm Ipq8074 FirmwareQualcomm Mdm9206 Firmware+4529/10/201817/6/2026
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6564, QCA6574, QCA6574AU,…
AnalizadaMedia (6.1)0.95%—Wago 750-362 FirmwareWago 750-363 FirmwareWago 750-823 FirmwareWago 750-832 Firmware+1012/10/201817/6/2026
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
ModificadaCrítica (9.8)2.1%—Fujixerox Docucentre-v 3065 FirmwareFujixerox Apeosport-v C4475 FirmwareFujixerox Apeosport-vi C3371 FirmwareFujixerox Apeosport-v C3375 Firmware+57/9/201817/6/2026
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices allow remote attackers to read or write to files via crafted PJL commands.
ModificadaAlta (7.8)11%—HP T8x44 FirmwareHP 3aw51a FirmwareHP A9u28b FirmwareHP D3a82a Firmware+26613/8/201817/6/2026
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.
ModificadaCrítica (9.8)12%—HP T8x44 FirmwareHP 3aw51a FirmwareHP A9u28b FirmwareHP D3a82a Firmware+26613/8/201817/6/2026
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.