Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.25%—T-head Xuantie C910AIT-head Th1520AIT-head Xuantie C920AISophon Sg2042AI19/8/202417/6/2026
The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.
ModificadaAlta (7.5)1.1%—Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+809/3/202016/6/2026
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
ModificadaCrítica (9.8)3.7%—Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+613/2/202017/6/2026
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
ModificadaCrítica (9.8)2.7%—Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+613/2/202017/6/2026
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
ModificadaBaja (3.5)1.7%—Lexmark C52xLexmark C53xLexmark C920Lexmark C935dn+54/2/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allow remote…
ModificadaAlta (10)3.3%—Lexmark 25xxnLexmark C52xLexmark C53xLexmark C77x+194/2/201416/6/2026
cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344, X64xef through LC2.TI.P325, C935dn through LC.JO.P091, C920 through LS.TA.P152, C78x through…
ModificadaAlta (7.8)1.2%—Lexmark 25xxnLexmark C510Lexmark C52xLexmark C53x+574/5/201016/6/2026
The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header.