Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.23%—Openbk7231tAI5/8/202626/8/2026
OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, "<h3>OTA requested for %s!</h3>", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an…
AplazadaAlta (8.5)0.28%—Openbk7231tAI5/8/202626/8/2026
OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in src/httpserver/http_fns.c with no HTML…
AplazadaMedia (6.5)0.17%—Openbk7231tAI5/8/202626/8/2026
OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string.
AnalizadaAlta (7.8)0.16%—Molotovcherry Android-imagemagick724/3/202617/6/2026
Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaCrítica (9.8)0.50%—Molotovcherry Android-imagemagick724/3/202617/6/2026
CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaMedia (6.1)0.24%—Molotovcherry Android-imagemagick724/3/202617/6/2026
CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaAlta (7.5)0.44%—Molotovcherry Android-imagemagick724/3/202617/6/2026
Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaAlta (7.5)0.44%—Molotovcherry Android-imagemagick724/3/202617/6/2026
Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaAlta (7.5)0.27%—Molotovcherry Android-imagemagick724/3/202617/6/2026
Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
AnalizadaCrítica (9.8)0.41%—Molotovcherry Android-imagemagick724/3/202617/6/2026
Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.
AnalizadaAlta (7.5)0.27%—Molotovcherry Android-imagemagick724/3/202617/6/2026
NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.
AnalizadaMedia (6.9)0.21%—HP M9l65a FirmwareHP D9l20a FirmwareHP K7s32a FirmwareHP D9l21a Firmware+3710/2/202617/6/2026
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS).…
AnalizadaMedia (6.9)0.28%—HP D9l18a FirmwareHP M9l66a FirmwareHP M9l67a FirmwareHP T0g46a Firmware+1310/2/202617/6/2026
Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.
AnalizadaAlta (8.8)0.78%—Dormakabagroup Dormakaba Access Manager 9200-k7 FirmwareDormakabagroup Dormakaba Access Manager 9230-k7 FirmwareDormakabagroup Dormakaba Access Manager 9290-k7 FirmwareDormakabagroup Dormakaba Access Manager 9200-k5 Firmware+226/1/202617/6/2026
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest…
AplazadaAlta (7)0.11%—K7AIK5AI26/1/202617/6/2026
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain…
AnalizadaAlta (7.7)0.15%—K7computing K7 Ultimate Security22/12/202517/6/2026
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key,…
AplazadaAlta (7.2)0.54%—K7 Security Anti-malwareAIK7 Rkscan.sysAI9/9/202517/6/2026
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized…
AplazadaMedia (5.6)0.23%—K7 Security Anti-malwareAIK7 Rkscan.sysAI11/6/202517/6/2026
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating…
AnalizadaCrítica (9.8)18%—Fortinet FortiwebFortinet FortiswitchmanagerFortinet FortiswitchFortinet Fortiproxy+424/3/202517/6/2026
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below…
ModificadaMedia (5.5)0.99%—K7computing K7 Ultimate Security6/8/202417/6/2026
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.
AnalizadaMedia (6.3)0.21%—HP 26k70b FirmwareHP 297x1a FirmwareHP 2a9q5a FirmwareHP 26k72a Firmware+2427/3/202417/6/2026
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.
ModificadaAlta (7.5)0.85%—HP Officejet PRO 8730 D9l19a FirmwareHP Officejet PRO 8730 M9l74a FirmwareHP Officejet PRO 8730 M9l75a FirmwareHP Officejet PRO 8730 M9l76a Firmware+814/12/202317/6/2026
Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.
ModificadaAlta (8.7)0.96%—Siemens 6gk7243-8rx30-0xe0 FirmwareSiemens 6gk7543-1ax00-0xe0 FirmwareSiemens 6ag1543-1ax00-2xe0 FirmwareSiemens Simatic CP 1242-7 V2 Firmware+512/12/202317/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),…
ModificadaCrítica (9.8)1.5%—HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+269612/12/202217/6/2026
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
ModificadaCrítica (9.8)1.3%—HP P4c78a FirmwareHP P4c85a FirmwareHP T3p03a FirmwareHP P4c86a Firmware+9526/9/202217/6/2026
Certain HP Print Products are potentially vulnerable to Buffer Overflow.