Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.22% | — | Realme GT 2AI | 14/5/2025 | 5/7/2026 | An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function. | |
| Aplazada | Alta (8.6) | 0.58% | — | Chinamobile P22g-ciacAIChinamobile Zxwt-mig-p4g4vAIChinamobile Zxwt-mig-p8g8vAIChinamobile Gt3200-4g4pAI+1 | 17/3/2025 | 17/6/2026 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been rated as critical. This issue affects some unknown processing of the component CLI su Command Handler. The manipulation leads to use of default credentials. The attack may be… | |
| Aplazada | Media (4.8) | 0.24% | — | Chinamobile P22g-ciacAIChinamobile Zxwt-mig-p4g4vAIChinamobile Zxwt-mig-p8g8vAIChinamobile Gt3200-4g4pAI+1 | 17/3/2025 | 17/6/2026 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be… | |
| Modificada | Alta (7.5) | 0.68% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards. | |
| Modificada | Media (6.1) | 0.58% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client. | |
| Modificada | Media (5.3) | 0.95% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected. | |
| Modificada | Crítica (9.8) | 1.9% | — | Windriver VxworksSiemens Sgt-100 FirmwareSiemens Sgt-200 FirmwareSiemens Sgt-300 Firmware+4 | 11/3/2021 | 17/6/2026 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Crítica (9.8) | 1.9% | — | Weidmueller Ie-sw-pl09m-5gc-4gt FirmwareWeidmueller Ie-sw-pl09mt-5gc-4gt FirmwareWeidmueller Ie-sw-pl18m-2gc-16tx FirmwareWeidmueller Ie-sw-pl18mt-2gc-16tx Firmware+36 | 6/12/2019 | 17/6/2026 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the network. | |
| Modificada | Media (6.5) | 1.1% | — | Weidmueller Ie-sw-pl09m-5gc-4gt FirmwareWeidmueller Ie-sw-pl09mt-5gc-4gt FirmwareWeidmueller Ie-sw-pl18m-2gc-16tx FirmwareWeidmueller Ie-sw-pl18mt-2gc-16tx Firmware+36 | 6/12/2019 | 17/6/2026 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Weidmueller Ie-sw-pl09m-5gc-4gt FirmwareWeidmueller Ie-sw-pl09mt-5gc-4gt FirmwareWeidmueller Ie-sw-pl18m-2gc-16tx FirmwareWeidmueller Ie-sw-pl18mt-2gc-16tx Firmware+36 | 6/12/2019 | 17/6/2026 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext. | |
| Modificada | Media (6.5) | 1.9% | — | Weidmueller Ie-sw-pl09m-5gc-4gt FirmwareWeidmueller Ie-sw-pl09mt-5gc-4gt FirmwareWeidmueller Ie-sw-pl18m-2gc-16tx FirmwareWeidmueller Ie-sw-pl18mt-2gc-16tx Firmware+36 | 6/12/2019 | 17/6/2026 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption. | |
| Modificada | Crítica (9.8) | 2.0% | — | Weidmueller Ie-sw-pl09m-5gc-4gt FirmwareWeidmueller Ie-sw-pl09mt-5gc-4gt FirmwareWeidmueller Ie-sw-pl18m-2gc-16tx FirmwareWeidmueller Ie-sw-pl18mt-2gc-16tx Firmware+36 | 6/12/2019 | 17/6/2026 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention. | |
| Modificada | Alta (7.5) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. | |
| Modificada | Alta (8.8) | 0.86% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. | |
| Modificada | Media (5.3) | 1.6% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images. | |
| Modificada | Crítica (9.8) | 2.3% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 6/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. | |
| Modificada | Crítica (9) | 2.7% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728). | |
| Modificada | Crítica (9.1) | 4.5% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. | |
| Modificada | Media (5.3) | 1.9% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user. | |
| Modificada | Alta (8.1) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731). | |
| Modificada | Crítica (9.8) | 3.1% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 12/1/2018 | 17/6/2026 | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain… | |
| Modificada | Media (5.3) | 1.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 12/1/2018 | 17/6/2026 | An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information. | |
| Modificada | Alta (10) | 2.7% | — | Netgear Wgt624 | 6/3/2006 | 16/6/2026 | NETGEAR WGT624 Wireless DSL router has a default account of super_username "Gearguy" and super_passwd "Geardog", which allows remote attackers to modify the configuration. NOTE: followup posts have suggested that this might not occur with all WGT624 routers. | |
| Modificada | Media (5) | 2.3% | — | Netgear Wgt624 | 6/3/2006 | 16/6/2026 | The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges. |