Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.57%—Tp-link Re305 FirmwareTp-link Re360 FirmwareTp-link Re580d FirmwareTp-link Re650 Firmware+122/5/202623/7/2026
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of…
ModificadaMedia (5.3)0.87%—Lexmark X860 FirmwareLexmark X862 FirmwareLexmark X864 FirmwareLexmark X734 Firmware+299/3/202016/6/2026
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
ModificadaAlta (7.5)1.1%—Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+809/3/202016/6/2026
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
ModificadaAlta (7.8)0.23%—Diqee360 Firmware5/7/201817/6/2026
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard/$PRO_NAME/upgrade.sh or /sdcard/upgrage_360/upgrade.sh pathname.
ModificadaAlta (7.5)3.0%—Diqee360 Firmware5/7/201817/6/2026
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuum cleaner as root. The bug is in the function…