Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)3.8%—Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+15920/1/202617/6/2026
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
ModificadaCrítica (9.1)0.75%—Mitsubishielectric Fx3u-32mt/es FirmwareMitsubishielectric Fx3u-48mt/es FirmwareMitsubishielectric Fx3u-64mt/es FirmwareMitsubishielectric Fx3u-80mt/es Firmware+2126/11/202317/6/2026
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC…
ModificadaCrítica (9.1)0.85%—Mitsubishielectric Fx3g-14 Mr/ds FirmwareMitsubishielectric Fx3g-14 Mr/es FirmwareMitsubishielectric Fx3g-14 Mt/ds FirmwareMitsubishielectric Fx3g-14 Mt/dss Firmware+18613/10/202317/6/2026
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.
ModificadaAlta (8.1)0.68%—Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+1631/8/202317/6/2026
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
ModificadaCrítica (9.1)1.3%—Mitsubishielectric Fx3u-16mr/es FirmwareMitsubishielectric Fx3u-16mt/es FirmwareMitsubishielectric Fx3u-16mt/ess FirmwareMitsubishielectric Fx3u-32mr/es Firmware+14630/6/202317/6/2026
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.
ModificadaAlta (7.5)0.64%—Hikvision Ds-k1t320efwx FirmwareHikvision Ds-k1t320efx FirmwareHikvision Ds-k1t320ewx FirmwareHikvision Ds-k1t320ex Firmware+2215/6/202317/6/2026
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by…
ModificadaAlta (8.8)0.34%—Cisco Business 140ac Access Point FirmwareCisco Business 141acm FirmwareCisco Business 142acm FirmwareCisco Business 143acm Firmware+418/5/202317/6/2026
A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit…
ModificadaAlta (7.5)1.7%—Mitsubishielectric Q03udecpu FirmwareMitsubishielectric Q04udehcpu FirmwareMitsubishielectric Q04udpvcpu FirmwareMitsubishielectric Q04udvcpu Firmware+2815/6/202217/6/2026
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of…
ModificadaAlta (8.1)2.0%—Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaMedia (6.5)0.22%—Philips Patient Information Center IXPhilips Efficia CM Firmware27/12/202117/6/2026
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to C.0x and 4.0.
ModificadaCrítica (9.8)0.69%—Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+158/10/202117/6/2026
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The…
ModificadaAlta (8.1)0.89%—Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+148/10/202117/6/2026
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
ModificadaCrítica (9.8)1.6%—Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+148/10/202117/6/2026
An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.
ModificadaMedia (5.9)1.5%—Mitsubishielectric Q03/04/06/13/26udvcpu FirmwareMitsubishielectric Q04/06/13/26udpvcpu FirmwareMitsubishielectric Q03udecpu FirmwareMitsubishielectric Q04/06/10/13/20/26/50/100udehcpu Firmware+613/11/201917/6/2026
In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial number 21081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 21081 and prior, MELSEC-L Series L02/06/26CPU, L26CPU-BT: serial number 21101 and prior, L02/06/26CPU-P,…
ModificadaAlta (7.5)2.1%—Siemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 FirmwareSiemens Ek-ertec 200p FirmwareSiemens Simatic CFU PA Firmware+6210/10/201917/6/2026
Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.
ModificadaAlta (7.5)1.4%—Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 Firmware+3610/10/201917/6/2026
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
ModificadaAlta (7.1)1.2%—Medtronic Minimed 508 FirmwareMedtronic Minimed Paradigm 511 FirmwareMedtronic Minimed Paradigm 512 FirmwareMedtronic Minimed Paradigm 712 Firmware+1528/6/201917/6/2026
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access…
ModificadaAlta (7.5)1.3%—ZTE Zxiptv-ucm Firmware25/7/201817/6/2026
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.
ModificadaAlta (8.7)3.3%—Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+3426/12/201717/6/2026
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaAlta (7.1)1.1%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+8911/5/201717/6/2026
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.