Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)6.4%—Linksys E9450-sg Firmware19/12/202530/9/2026
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.
AnalizadaAlta (7.8)0.17%—Dell PRO Rugged 13 Ra13250 FirmwareDell PRO Rugged 14 Rb14250 FirmwareDell Latitude 5350 FirmwareDell Latitutde 5450 Firmware+1025/9/202517/6/2026
Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code Execution.
AnalizadaMedia (6.7)0.17%—Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+2579/4/202517/6/2026
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaAlta (8.2)0.17%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+38819/2/202517/6/2026
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
ModificadaMedia (6.5)0.31%—Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+11611/4/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the…
ModificadaAlta (7.5)0.96%—Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+4527/4/202217/6/2026
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
ModificadaMedia (5.3)0.79%—Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+4527/4/202217/6/2026
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
ModificadaMedia (5.3)0.79%—Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+4527/4/202217/6/2026
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
ModificadaAlta (10)4.6%—GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+54/2/201416/6/2026
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary…
ModificadaAlta (10)1.7%—GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+54/2/201416/6/2026
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors.