Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 356 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Linksys E2500 Firmware | 21/7/2025 | 5/7/2026 | In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks. | |
| Modificada | Alta (8) | 0.76% | — | Linksys E2500 Firmware | 24/7/2024 | 9/7/2026 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function. | |
| Modificada | Alta (7.5) | 1.1% | — | Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+80 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. | |
| Modificada | Alta (7.2) | 4.8% | — | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control… | |
| Modificada | Alta (7.2) | 3.4% | — | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web… | |
| Modificada | Alta (7.2) | 14% | — | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM. Data entered into the 'Router Name' input field through the web… | |
| Modificada | Baja (3.5) | 1.7% | — | Lexmark C52xLexmark C53xLexmark C920Lexmark C935dn+5 | 4/2/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allow remote… | |
| Modificada | Alta (10) | 3.3% | — | Lexmark 25xxnLexmark C52xLexmark C53xLexmark C77x+19 | 4/2/2014 | 16/6/2026 | cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344, X64xef through LC2.TI.P325, C935dn through LC.JO.P091, C920 through LS.TA.P152, C78x through… | |
| Modificada | Alta (7.8) | 2.5% | — | Ovislink Airlive Od-2025hdOvislink Airlive Od-2060hdOvislink Airlive Poe100hdOvislink Airlive Poe200hd+2 | 11/10/2013 | 16/6/2026 | AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwords, user names, and other sensitive information by reading an unspecified backup file. | |
| Modificada | Media (6.8) | 0.97% | — | Ovislink Airlive Od-2025hdOvislink Airlive Od-2060hdOvislink Airlive Poe100hdOvislink Airlive Poe200hd+2 | 4/10/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users. | |
| Modificada | Alta (7.8) | 1.2% | — | Lexmark 25xxnLexmark C510Lexmark C52xLexmark C53x+57 | 4/5/2010 | 16/6/2026 | The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header. |