Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.13%—Tp-link Tapo L535e FirmwareTp-link Tapo P300 FirmwareTp-link Tapo D100c Firmware28/5/202617/6/2026
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range could exploit this…
AplazadaMedia (6.5)0.54%—Rockgod100 Theme File DuplicatorAI17/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator allows Path Traversal.This issue affects Theme File Duplicator: from n/a through <= 1.3.
AplazadaCrítica (9.9)0.54%—Rockgod100 Theme File DuplicatorAI17/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator allows Using Malicious Files.This issue affects Theme File Duplicator: from n/a through <= 1.3.
ModificadaAlta (7.8)1.4%—NXP Lpc55s66jbd64 FirmwareNXP Lpc55s66jbd100 FirmwareNXP Lpc55s66jev98 FirmwareNXP Lpc55s69jbd64 Firmware+223/3/202217/6/2026
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.
ModificadaAlta (7.8)0.20%—Schneider-electric Hmibmuhi29d2801 FirmwareSchneider-electric Hmibmusi29d2801 FirmwareSchneider-electric Hmibmuci29d2w01 FirmwareSchneider-electric Hmibmu0i29d2001 Firmware+339/2/202217/6/2026
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer…
ModificadaMedia (5.5)0.77%—NXP Lpc55s69jbd100 FirmwareNXP Lpc55s69jbd64 FirmwareNXP Lpc55s69jev98 Firmware1/12/202117/6/2026
NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
ModificadaMedia (6.8)0.45%—NXP Lpc55s69jbd100 FirmwareNXP Lpc55s66jbd100 FirmwareNXP Lpc55s69jev98 FirmwareNXP Lpcs66jev98 Firmware+206/5/202117/6/2026
NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent…
ModificadaAlta (7.5)0.54%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. A custom encryption…
ModificadaCrítica (9.8)1.5%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default…
ModificadaCrítica (9.8)1.5%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default…
ModificadaCrítica (9.8)1.5%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default…
ModificadaCrítica (9.8)1.5%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default…
ModificadaCrítica (9.8)1.5%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can discover…
ModificadaAlta (7.5)1.9%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. It allows remote…
ModificadaCrítica (9.8)2.0%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2524/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. One can escape from a…
ModificadaMedia (5.9)0.67%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. By default, the…
ModificadaCrítica (9.8)1.4%—Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+2424/11/202017/6/2026
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can use…
ModificadaAlta (7.8)0.51%—Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+10822/7/202017/6/2026
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
ModificadaAlta (7.5)1.1%—Jpmd100b Project Jpmd100b9/7/201817/6/2026
The mintToken function of a smart contract implementation for JPMD100B, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)82%—EIR D1000 Modem Firmware16/5/201717/6/2026
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.
ModificadaMedia (4.3)1.5%—Sourcefire 3d1000Sourcefire 3d2000Sourcefire 3d9900Sourcefire Dc100016/6/201016/6/2026
The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack.
ModificadaAlta (7.8)0.91%—Huawei D1001/7/200916/6/2026
The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against reading file contents.
ModificadaMedia (5)0.66%—Huawei D100 Firmware1/7/200916/6/2026
The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (7.5)0.64%—Huawei D100 Firmware1/7/200916/6/2026
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.
ModificadaAlta (10)1.3%—Huawei D1001/7/200916/6/2026
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.