Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.31% | — | NetxAIFilexAI | 29/9/2026 | 29/9/2026 | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both… | |
| Analizada | Alta (8.7) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration. | |
| Analizada | Media (5.1) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication. | |
| Analizada | Media (6.9) | 0.60% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition. | |
| Analizada | Alta (7.1) | 0.46% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet. | |
| Analizada | Alta (8.2) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack. | |
| Analizada | Media (6.9) | 0.40% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication. | |
| Analizada | Crítica (9.3) | 0.71% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Alta (8.7) | 0.65% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Crítica (9.2) | 0.51% | — | Eclipse Threadx Filex | 16/10/2025 | 17/6/2026 | In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It could cause a remote execurtion after receiving a crafted sequence of packets | |
| Analizada | Alta (8.5) | 0.17% | — | Intel Agilex 7 Fpga Firmware | 14/8/2024 | 17/6/2026 | improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access. | |
| Aplazada | Alta (7.6) | 0.33% | — | Intel Stratix 10 FirmwareAIIntel Agilex 7 FirmwareAI | 16/5/2024 | 17/6/2026 | Unchecked return value in SDM firmware for Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs before version 23.3 may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (6.8) | 0.33% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command. | |
| Analizada | Crítica (9.1) | 0.57% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command. | |
| Analizada | Alta (7.5) | 0.55% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Agilex 7 Fpga F-series 006 FirmwareIntel Agilex 7 Fpga F-series 008 FirmwareIntel Agilex 7 Fpga F-series 012 FirmwareIntel Agilex 7 Fpga F-series 014 Firmware+44 | 14/11/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 1.0% | — | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (6.1) | 0.38% | — | Chilexpress-oficial | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <= 1.2.9 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Agilex 7 Fpga F-series 019 FirmwareIntel Agilex 7 Fpga F-series 023 FirmwareIntel Agilex 7 Fpga F-series 006 FirmwareIntel Agilex 7 Fpga F-series 008 Firmware+44 | 10/5/2023 | 17/6/2026 | Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.89% | — | Microsoft Azure Rtos Filex | 8/11/2022 | 17/6/2026 | Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory contents. When a valid log file with… | |
| Modificada | Alta (7.8) | 0.90% | — | Ilex International Sign&go | 10/11/2020 | 9/7/2026 | Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log. | |
| Modificada | Media (6.5) | 1.6% | — | Trilexnet LetodmsDebian Linux | 13/11/2019 | 16/6/2026 | letodms 3.3.6 has CSRF via change password |