Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 30/9/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Baja (2.1) | 4.0% | — | Dlink Di-7100g C1 Firmware | 9/2/2026 | 17/6/2026 | A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.3) | 3.5% | — | Dlink Di-7100g C1 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sa9000p FirmwareQualcomm Sar2130p FirmwareQualcomm Snapdragon 8 Gen1 5G FirmwareQualcomm Sd662 Firmware+149 | 2/2/2026 | 17/6/2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Analizada | Alta (7.4) | 0.96% | — | Dlink Di-7100g C1 Firmware | 6/10/2025 | 17/6/2026 | A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.4) | 1.00% | — | Dlink Di-7100g C1 Firmware | 6/10/2025 | 17/6/2026 | A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published… | |
| Analizada | Baja (2) | 4.6% | — | Dlink Di-7100g C1 Firmware | 6/10/2025 | 17/6/2026 | A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the argument iface causes command injection. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Baja (2.6) | 0.31% | — | Macro-video V380e6 C1 Firmware | 18/4/2025 | 17/6/2026 | An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components. | |
| Analizada | Media (6.8) | 0.38% | — | Macro-video V380e6 C1 Firmware | 18/4/2025 | 17/6/2026 | An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component. | |
| Modificada | Media (4.6) | 0.15% | — | Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+87 | 4/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated. | |
| Modificada | Media (6.6) | 0.12% | — | Eaton Easy-box-e4-ac1 FirmwareEaton Easy-box-e4-dc1 FirmwareEaton Easy-box-e4-uc1 FirmwareEaton Easy-e4-ac-12rc1p Firmware+18 | 17/10/2023 | 17/6/2026 | Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending). | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Media (6.1) | 0.90% | — | Mitsubishielectric Mac-587if-e FirmwareMitsubishielectric Mac-587if2-e FirmwareMitsubishielectric Mac-507if-e FirmwareMitsubishielectric Mac-588if-e Firmware+115 | 8/11/2022 | 17/6/2026 | Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and… | |
| Modificada | Crítica (9.8) | 0.97% | — | Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+174 | 8/11/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy… | |
| Modificada | Crítica (9.1) | 0.61% | — | Sick Flx3-cpuc1 FirmwareSick Flx3-cpuc2 Firmware | 31/10/2022 | 17/6/2026 | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact. | |
| Modificada | Alta (7.5) | 0.76% | — | Festo Cpx-cmxx FirmwareFesto Cpx-cec-c1 Firmware | 20/9/2022 | 17/6/2026 | Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Alta (7.8) | 0.27% | — | Asus Vc65-c1 FirmwareAsus Pb60v FirmwareAsus Pb60g FirmwareAsus Pb60s Firmware+9 | 21/1/2022 | 17/6/2026 | ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service. | |
| Modificada | Baja (3.4) | 0.30% | — | ARM Cortex-m33 FirmwareARM Cortex-m35p FirmwareARM Cortex-m55 FirmwareARM China Star-mc1 Firmware | 23/8/2021 | 17/6/2026 | Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33 r0p0 through r1p0, Arm Cortex-M35P r0, Arm Cortex-M55 r0p0 through r1p0, and Arm China STAR-MC1… | |
| Modificada | Crítica (9.8) | 1.6% | — | Dlink Dir-600 B1 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-645 A1 FirmwareDlink Dir-815 A1 Firmware+3 | 11/11/2019 | 17/6/2026 | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00. | |
| Modificada | Alta (7.5) | 1.1% | — | Honeywell H4d8pr1 FirmwareHoneywell Hfd5pr1 FirmwareHoneywell Hpw2p1 FirmwareHoneywell Hdzp304di Firmware+44 | 31/10/2019 | 17/6/2026 | Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP. | |
| Modificada | Crítica (9.8) | 1.4% | — | Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+60 | 31/10/2019 | 17/6/2026 | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products. | |
| Modificada | Crítica (9.8) | 4.1% | — | Motorola M2 FirmwareMotorola C1 Firmware | 7/3/2019 | 17/6/2026 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST… | |
| Modificada | Crítica (9.8) | 6.2% | — | Motorola M2 FirmwareMotorola C1 Firmware | 7/3/2019 | 17/6/2026 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST… |