Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1343▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.3% | — | Tp-link Ue330 Firmware | 11/8/2021 | 17/6/2026 | TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB… | |
| Modificada | Alta (7.5) | 1.1% | — | Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+80 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. | |
| Modificada | Alta (7.5) | 1.5% | — | Emerson Rx3i Cpe100 FirmwareEmerson Rx3i Cpe115 FirmwareEmerson Rx3i Cpe302 FirmwareEmerson Rx3i Cpe305 Firmware+5 | 16/1/2020 | 17/6/2026 | GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must… | |
| Modificada | Alta (7.5) | 3.4% | — | GE Pacsystems Rx3i Cpe305 FirmwareGE Pacsystems Rx3i Cpe310 FirmwareGE Rx3i Cpe330 FirmwareGE Rx3i CPE 400 Firmware+4 | 18/5/2018 | 17/6/2026 | In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially… |