Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.17% | — | Milesight IOT DevicesAI | 26/8/2026 | 9/9/2026 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The… | |
| Aplazada | Crítica (9.2) | 0.51% | — | Naxclow DevicesAI | 12/6/2026 | 17/6/2026 | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce… | |
| Pendiente de análisis | Alta (7.4) | 0.98% | — | Crestron DevicesAI | 5/5/2026 | 24/7/2026 | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices… | |
| Aplazada | Alta (8.4) | 0.19% | — | Flipper Devices Flipperzero FirmwareAI | 1/5/2026 | 17/6/2026 | flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function. | |
| Analizada | Crítica (9.8) | 1.6% | — | Microsoft Devices Pricing Program | 5/3/2026 | 17/6/2026 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI | 2/3/2026 | 17/6/2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | |
| Aplazada | Crítica (9.3) | 0.66% | — | Raisecom DevicesAI | 21/10/2025 | 17/6/2026 | The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials. | |
| Aplazada | Media (6.3) | 0.13% | — | Bluebird DevicesAI | 17/7/2025 | 17/6/2026 | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.… | |
| Aplazada | Media (5.1) | 0.14% | — | Tinxy Smart DevicesAI | 11/3/2025 | 17/6/2026 | This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device. | |
| Aplazada | Alta (8.1) | 0.18% | — | Lexmark DevicesAI | 19/2/2025 | 17/6/2026 | Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device. | |
| Aplazada | Crítica (9.4) | 0.17% | — | Infinix DevicesAI | 4/12/2024 | 17/6/2026 | Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions. After multiple attempts to contact the vendor we did not… | |
| Aplazada | Alta (7) | 0.15% | — | Philips Lighting DevicesAI | 25/10/2024 | 17/6/2026 | This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device.… | |
| Aplazada | Alta (8.4) | 0.84% | — | Gehealthcare Ultrasound DevicesAI | 14/5/2024 | 17/6/2026 | OS command injection vulnerabilities in GE HealthCare ultrasound devices | |
| Aplazada | Media (6.3) | 0.25% | — | Lenovo DevicesAISynaptics Fingerprint ReaderAIMicrosoft Windows HelloAI | 5/4/2024 | 17/6/2026 | An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication. | |
| Aplazada | Alta (8.8) | 0.34% | — | Silabs Z-wave END DevicesAI | 7/3/2024 | 17/6/2026 | The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | |
| Modificada | Media (6.6) | 98% | — | Apache Log4jOracle Communications Diameter Signaling RouterOracle Communications Interactive Session RecorderOracle Primavera Gateway+18 | 28/12/2021 | 17/6/2026 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting… | |
| Modificada | Alta (7.8) | 0.26% | — | Pandasecurity Panda Adaptive Defense 360Pandasecurity Panda Devices Agent | 23/9/2021 | 17/6/2026 | DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file. | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a… | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to exhaust device BT resources and eventually trigger a crash via… | |
| Modificada | Media (5.3) | 0.51% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a… | |
| Modificada | Crítica (9.1) | 1.6% | — | Oracle Customer Relationship Management Gateway FOR Mobile Devices | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway… | |
| Modificada | Crítica (9.1) | 1.6% | — | Oracle Customer Relationship Management Gateway FOR Mobile Devices | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway… | |
| Modificada | Media (6.1) | 99% | — | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Baja (3.7) | 8.1% | — | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Alta (8.6) | 1.7% | — | Oracle Customer Relationship Management Gateway FOR Mobile Devices | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway… |