Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.7)0.16%—Solidigm DC FirmwareAI7/10/202417/6/2026
Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.
ModificadaMedia (4.6)0.15%—Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+874/9/202417/6/2026
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.
AnalizadaMedia (5.1)4.7%—Edimax Ic-6220dc FirmwareEdimax Ic-5150w Firmware12/8/202417/6/2026
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The vendor was contacted early about this disclosure but did not…
ModificadaCrítica (9.1)1.4%—Korenix Jetnet 5310g FirmwareKorenix Jetnet 4508 FirmwareKorenix Jetnet 4508i-w FirmwareKorenix Jetnet 4508-w Firmware+389/1/202417/6/2026
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.
ModificadaCrítica (9.1)1.3%—Korenix Jetnet 5310g FirmwareKorenix Jetnet 4508 FirmwareKorenix Jetnet 4508i-w FirmwareKorenix Jetnet 4508-w Firmware+389/1/202417/6/2026
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
ModificadaAlta (8.8)0.96%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
ModificadaAlta (8.8)1.2%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi…
ModificadaAlta (7.5)1.3%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
ModificadaAlta (8.8)1.0%—Dcnetworks Dcfw-1800-sdc Firmware4/10/202317/6/2026
File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
ModificadaMedia (5.9)0.38%—Ls-electric Xg5000Ls-electric Xgk-cpuun FirmwareLs-electric Xgk-cpuhn FirmwareLs-electric Xgk-cpusn Firmware+23131/8/202217/6/2026
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of…
ModificadaCrítica (9.8)16%—ABB Rmc-100 FirmwareABB Rmc-100-lite FirmwareABB XIO FirmwareABB Xfcg5 Firmware+321/7/202217/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an…
ModificadaCrítica (9.8)1.3%—Nexans Gigaswitch 641 Desk V5 Sfp-vi FirmwareNexans Gigaswitch 642 Desk V5 Sfp-2vi FirmwareNexans Gigaswitch V5 2tp(pd-f+) Sfp-vi 54vdc FirmwareNexans Gigaswitch V5 2tp(pse+) Sfp-vi 54vdc Firmware+917/7/202217/6/2026
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
ModificadaAlta (8.1)1.7%—Cisco Sf250-24 FirmwareCisco Sf250-24p FirmwareCisco Sf250-48 FirmwareCisco Sf250-48hp Firmware+2054/11/202117/6/2026
A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerability is due to…
ModificadaAlta (7.8)0.22%—Cisco Aironet 1542d FirmwareCisco Aironet 1562d FirmwareCisco Aironet 1815m FirmwareCisco Aironet 1830e Firmware+3723/9/202117/6/2026
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A…
ModificadaCrítica (9.8)1.6%—Qnap Ej1600 FirmwareQnap Tl-r1620sdc FirmwareQnap Tl-r1620sep-rp FirmwareQnap Tl-r1220sep-rp Firmware+1010/9/202117/6/2026
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03…
ModificadaMedia (6.5)2.9%—Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+19011/5/202117/6/2026
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
ModificadaMedia (5.3)6.5%—NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+16211/5/202117/6/2026
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to…
ModificadaBaja (2.6)2.6%—Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+16411/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or…
ModificadaMedia (6)0.26%—Dell Dock Wd15 FirmwareDell Dock Wd19 FirmwareDell Thunderbolt Dock Tb16 FirmwareDell Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware28/5/202017/6/2026
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally…
ModificadaAlta (7.5)1.7%—Siemens KTK Ate530s FirmwareSiemens Sidoor Atd430w FirmwareSiemens Sidoor Ate530s Coated FirmwareSiemens Sidoor Ate531s Firmware+2914/4/202017/6/2026
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L…
ModificadaMedia (6.5)1.2%—Fortinet Fortiadc Firmware7/4/202017/6/2026
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.
ModificadaMedia (5.4)0.63%—Fortinet Fortiadc Firmware7/4/202017/6/2026
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
ModificadaMedia (6.5)1.1%—Barracuda Load Balancer ADC Firmware12/3/202017/6/2026
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any…
ModificadaMedia (6.8)0.34%—Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+14419/8/201917/6/2026
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
ModificadaAlta (7.5)1.8%—Cisco Sf200-24 FirmwareCisco Sf200-24p FirmwareCisco Sf200-48 FirmwareCisco Sf200-48p Firmware+536/7/201917/6/2026
A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker…