Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
497 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+110 | 5/6/2023 | 17/6/2026 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.86% | — | Sprecher-automation Sprecon-e-p Dq6-1 FirmwareSprecher-automation Sprecon-e-p Dl6-1 FirmwareSprecher-automation Sprecon-e-p Ds6-0 FirmwareSprecher-automation Sprecon-e-c Firmware+5 | 1/6/2023 | 17/6/2026 | Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+161 | 2/5/2023 | 17/6/2026 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8052 Firmware+216 | 2/5/2023 | 17/6/2026 | Memory corruption in Graphics while importing a file. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Mdm8207 Firmware+9 | 2/5/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+36 | 2/5/2023 | 17/6/2026 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. | |
| Modificada | Alta (8.8) | 0.51% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |
| Modificada | Alta (8.8) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |
| Modificada | Media (5.9) | 0.45% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | |
| Modificada | Media (4.9) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured | |
| Modificada | Media (6.5) | 0.36% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. | |
| Modificada | Alta (8.8) | 0.50% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+222 | 13/4/2023 | 17/6/2026 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | |
| Modificada | Crítica (9.8) | 0.42% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in modem while reading configuration parameters. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Mdm8207 Firmware+9 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. |