Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.7)0.42%—Hitachienergy Rtu540 FirmwareHitachienergy Rtu560 FirmwareHitachienergy Rtu520 FirmwareHitachienergy Rtu530 Firmware24/2/202617/6/2026
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of…
AnalizadaMedia (5.3)0.27%—Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware24/2/202617/6/2026
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
AnalizadaAlta (7.3)7.5%—UTT 520 Firmware20/2/202617/6/2026
A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the component Web Management Interface. The manipulation of the argument Isp_Name results in os command injection. The attack can be launched remotely. The exploit is now public and…
AnalizadaAlta (7.3)7.5%—UTT 520 Firmware20/2/202617/6/2026
A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (4.9)0.31%—Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+10825/9/202517/6/2026
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (8.7)1.6%—Dlink Dap-1520 Firmware6/5/202517/6/2026
A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been declared as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The…
AnalizadaAlta (8.7)1.2%—Dlink Dap-1520 Firmware6/5/202517/6/2026
A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (8.7)1.2%—Dlink Dap-1520 Firmware6/5/202517/6/2026
A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02 and classified as critical. Affected by this issue is the function check_dws_cookie of the file /storage. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (6.7)0.17%—Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+2579/4/202517/6/2026
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaAlta (8.2)0.17%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+38819/2/202517/6/2026
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaMedia (5.3)0.73%—Dlink Dap-1520 Firmware17/12/202417/6/2026
A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist_new.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/tool/traceroute.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.php.
AnalizadaCrítica (9.8)0.75%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/license_update.php.
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
AnalizadaMedia (6.7)0.15%—Dell Latitude 5290 2-in-1 FirmwareDell Precision 3420 Tower FirmwareDell Precision 3620 FirmwareDell Wyse 7040 Thin Client Firmware+3714/8/202417/6/2026
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
ModificadaMedia (6)0.17%—Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 FirmwareDell Precision 3930 Rack FirmwareDell Optiplex 7080 Firmware+624/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
AnalizadaMedia (4.4)0.13%—Dell Inspiron 3480 FirmwareDell Inspiron 3580 FirmwareDell Latitude 3120 FirmwareDell Latitude 3190 Firmware+7025/6/202417/6/2026
Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
ModificadaAlta (7.5)0.19%—Omron Nj101-1000 FirmwareOmron Nj101-1020 FirmwareOmron Nj101-9000 FirmwareOmron Nj101-9020 Firmware+5124/6/202417/6/2026
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.
ModificadaMedia (6.8)0.25%—Dell XPS 17 9700 FirmwareDell XPS 15 9500 FirmwareDell Vostro 7500 FirmwareDell Precision 5750 Firmware+1112/6/202417/6/2026
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
AnalizadaMedia (6.7)0.21%—Dell Edge Gateway 5000 FirmwareDell Precision 5820 Tower FirmwareDell Edge Gateway 3000 FirmwareDell Embedded BOX PC 3000 Firmware+4617/5/202417/6/2026
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.