Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
26.338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.52% | — | Fanvil X210 Firmware | 3/12/2025 | 25/9/2026 | Se descubrió un problema en Fanvil x210 V2 2.12.20 que permite a atacantes no autenticados en la red local acceder a funciones administrativas del dispositivo (por ejemplo, carga de archivos, actualización de firmware, reinicio...) mediante una elaborada omisión de autenticación. | |
| Analizada | Alta (7.5) | 0.33% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 2200 Firmware | 3/12/2025 | 17/6/2026 | An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service. | |
| Analizada | Media (5.3) | 0.29% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 1330 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 Firmware+14 | 3/12/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container lacks bounds checking, which can cause a… | |
| Modificada | Media (6.1) | 0.48% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field. | |
| Modificada | Alta (8.8) | 17% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Alta (8.8) | 3.3% | 💥 PoC | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Alta (8.8) | 2.8% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Media (6.5) | 2.4% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Analizada | Crítica (9.8) | 1.2% | 💥 PoC | Dlink R15 Firmware | 2/12/2025 | 17/6/2026 | A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd. | |
| Modificada | Media (4.6) | 0.26% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password. | |
| Modificada | Crítica (9.1) | 0.46% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB… | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components. | |
| Modificada | Media (4.1) | 0.19% | — | Entrust Nshield Connect XC High FirmwareEntrust Nshield Connect XC MID FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Hsmi Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted). | |
| Modificada | Baja (3.9) | 0.18% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection). | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader. | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06. | |
| Modificada | Baja (3.2) | 0.24% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board. | |
| Modificada | Crítica (9.8) | 0.67% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04. | |
| Modificada | Media (6.8) | 0.32% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the… | |
| Modificada | Crítica (9.8) | 0.90% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving… | |
| Analizada | Alta (8.5) | 0.37% | — | Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware | 2/12/2025 | 17/6/2026 | Vulnerabilidad de desbordamiento de búfer basado en pila en Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. En la función 'ShowMeterPasswords()', existe una entrada de usuario ilimitada que se copia a un búfer de tamaño fijo a través de 'sprintf()'. La función 'GetParameter(meter)' recupera la entrada del usuario, la cual se… | |
| Analizada | Alta (8.7) | 0.33% | — | Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware | 2/12/2025 | 17/6/2026 | Vulnerabilidad de desbordamiento de búfer basado en pila en Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. En la función 'showMeterReport()', existe una entrada de usuario ilimitada que se copia a un búfer de tamaño fijo a través de 'sprintf()'. La función 'GetParameter(meter)' recupera la entrada del usuario, la cual se… | |
| Analizada | Crítica (10) | 0.35% | — | Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware | 2/12/2025 | 17/6/2026 | Desbordamiento de búfer basado en pila en Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. Esta vulnerabilidad permite a un atacante explotar remotamente la corrupción de memoria a través de la función 'read_packet()' de la implementación de TACACSPLUS. |