Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.98% | — | Tendacn PA6 Firmware | 15/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Tenda PA6 1.0.1.21. Affected by this vulnerability is the function cgiPortMapAdd of the file /portmap of the component httpd. The manipulation of the argument groupName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.96% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.2% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi… | |
| Modificada | Alta (7.5) | 1.3% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information. | |
| Modificada | Alta (7.8) | 0.39% | — | Supermicro X12dai-n6 FirmwareSupermicro X12ddw-a6 FirmwareSupermicro X12dgo-6 FirmwareSupermicro X12dgq-r Firmware+267 | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable. | |
| Modificada | Crítica (9.8) | 2.1% | — | Supermicro H12dst-b FirmwareSupermicro X13dai-t FirmwareSupermicro X13ddw-a FirmwareSupermicro X13deg-oa Firmware+161 | 31/7/2023 | 17/6/2026 | A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC. | |
| Modificada | Media (5.5) | 0.15% | — | Supermicro X11ssl-cf FirmwareSupermicro X11dac FirmwareSupermicro X11dai-n FirmwareSupermicro X11ddw-l Firmware+142 | 7/4/2023 | 9/7/2026 | Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.34% | — | Lenovo 100e 2ND GEN FirmwareLenovo 100w GEN 3 FirmwareLenovo 13W Yoga FirmwareLenovo 14W GEN 2 Firmware+66 | 26/1/2023 | 17/6/2026 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | |
| Modificada | Baja (2.3) | 0.18% | — | Dell Alienware M15 A6 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 Ryzen Edition R5 FirmwareDell G15 5515 Firmware+11 | 18/1/2023 | 17/6/2026 | Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM. | |
| Modificada | Alta (7.5) | 0.17% | — | Dell Alienware M15 A6 FirmwareDell Alienware M17 R5 FirmwareDell G15 5525 Firmware | 18/1/2023 | 17/6/2026 | Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+182 | 11/10/2022 | 17/6/2026 | Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo A340-22icb FirmwareLenovo A340-22ick FirmwareLenovo A340-24icb FirmwareLenovo A340-24ick Firmware+49 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo Stadia Ggp-120 FirmwareLenovo Thinkedge Se30 FirmwareLenovo V540-24iwl FirmwareLenovo Thinkstation P520 Firmware+28 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 2.8% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.2% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+69 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.3% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.5) | 3.1% | — | Alfa Awus036h FirmwareCisco Meraki Gr10 FirmwareCisco Meraki Gr60 FirmwareCisco Meraki Mr20 Firmware+91 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP… | |
| Modificada | Alta (7.5) | 1.1% | — | Tendacn PA6 Firmware | 25/6/2020 | 17/6/2026 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot. | |
| Modificada | Alta (8.8) | 3.5% | — | Tendacn PA6 Firmware | 25/6/2020 | 17/6/2026 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to… | |
| Modificada | Alta (8.8) | 2.9% | — | Tendacn PA6 Firmware | 25/6/2020 | 17/6/2026 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges. | |
| Modificada | Alta (7.5) | 1.7% | — | Wavlink Wl-wn575a3 FirmwareWavlink Wl-wn579g3 FirmwareWavlink Wn531a6 FirmwareWavlink Wn535g3 Firmware+9 | 7/5/2020 | 17/6/2026 | An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4,… | |
| Modificada | Alta (7.5) | 1.8% | — | Wavlink Wl-wn579g3 FirmwareWavlink Wl-wn575a3 FirmwareWavlink Wl-wn530hg4 FirmwareWavlink Wn531g3 Firmware+11 | 27/4/2020 | 17/6/2026 | An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any… | |
| Modificada | Alta (8.1) | 1.1% | — | Haier A6 Project Haier A6 Firmware | 14/11/2019 | 17/6/2026 | The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named… | |
| Modificada | Media (5.5) | 0.29% | — | Haier A6 Firmware | 14/11/2019 | 17/6/2026 | The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an… |