Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.3%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+2119/11/202117/6/2026
During installation with certain driver software or application packages an arbitrary code execution could occur.
ModificadaAlta (7.5)23%💥 ExploitComprotech Ip70 FirmwareComprotech Ip570 FirmwareComprotech Ip60 FirmwareComprotech Tn540 Firmware1/9/202117/6/2026
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.
ModificadaAlta (7.5)23%💥 ExploitComprotech Ip70 FirmwareComprotech Ip570 FirmwareComprotech Ip60 FirmwareComprotech Tn540 Firmware1/9/202117/6/2026
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.
ModificadaAlta (7.5)23%💥 ExploitComprotech Ip70 FirmwareComprotech Ip570 FirmwareComprotech Ip60 FirmwareComprotech Tn540 Firmware1/9/202117/6/2026
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.
ModificadaAlta (7.5)22%💥 ExploitComprotech Ip70 FirmwareComprotech Ip570 FirmwareComprotech Ip60 FirmwareComprotech Tn540 Firmware1/9/202117/6/2026
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
ModificadaAlta (8.1)15%💥 ExploitComprotech Ip70 FirmwareComprotech Ip570 FirmwareComprotech Ip60 FirmwareComprotech Tn540 Firmware1/9/202117/6/2026
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.
ModificadaAlta (7.5)1.5%—Fujixerox Docucentre-vii C7773 FirmwareFujixerox Docucentre-vii C6673 FirmwareFujixerox Docucentre-vii C5573 FirmwareFujixerox Docucentre-vii C4473 Firmware+7125/3/202117/6/2026
Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort C7070/C6570/C5570/C4570/C3570/C3070/C7070G/C6570G/C5570G/C4570G/C3570G/C3070G,…
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaMedia (6.7)0.33%—Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
ModificadaMedia (6.8)0.28%—Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+969/6/202017/6/2026
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
ModificadaCrítica (9.8)3.7%—Lenovo B50-10 FirmwareLenovo Flex 2 Pro-15 FirmwareLenovo Edge 15 FirmwareLenovo Flex 3-1470 Firmware+2327/3/202017/6/2026
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code…
ModificadaBaja (3.9)0.15%—Huawei Hege-560 FirmwareHuawei Hege-570 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a Firmware+220/3/202017/6/2026
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions…
ModificadaMedia (5.3)0.35%—Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+17021/2/202017/6/2026
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring…
ModificadaMedia (4.4)0.25%—Dell G3 3579 FirmwareDell G3 3779 FirmwareDell G3 15 3590 FirmwareDell G5 15 5590 Firmware+10921/2/202017/6/2026
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit…
ModificadaMedia (6.1)0.21%—Huawei Hege-560 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a FirmwareHuawei Osca-550ax Firmware+218/2/202017/6/2026
Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device information. Successful exploit may cause service…
ModificadaMedia (5.5)1.4%💥 PoCCanonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+44117/1/202017/6/2026
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.5)1.2%—Lenovo Legion Y520t Z370 FirmwareLenovo Aio310-20iap FirmwareLenovo Aio510-22ish FirmwareLenovo Aio510-23ish Firmware+10429/8/201917/6/2026
There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH…
ModificadaMedia (6.8)0.36%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+2375/8/201917/6/2026
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.…
ModificadaAlta (7.8)0.40%—Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+5524/1/201917/6/2026
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
ModificadaMedia (5.9)0.53%—HP 310s-14isk FirmwareHP 320-15ikbra FirmwareHP 320-15ikbrn FirmwareHP 320-15ikbrn Touch Firmware+642/10/201817/6/2026
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
ModificadaMedia (6.8)0.53%—Lenovo E42-80 FirmwareLenovo E42-80 ISK FirmwareLenovo E52-80 FirmwareLenovo E52-80 ISK Firmware+3519/7/201817/6/2026
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.