Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6) | 0.17% | — | KVMAI | 14/5/2026 | 17/6/2026 | Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resulting in unauthorized access to privileged resources and loss of confidentiality. | |
| Analizada | Alta (8.5) | 0.66% | — | Angeet ES3 KVM Firmware | 17/3/2026 | 17/6/2026 | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands. | |
| Analizada | Crítica (9.3) | 0.57% | — | Angeet ES3 KVM Firmware | 17/3/2026 | 17/6/2026 | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a vulnerable system. | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Sipeed NanokvmAI | 17/3/2026 | 17/6/2026 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to change the saved configured Wi-Fi network to one of the attacker's choosing, or craft a request to exhaust the system memory and terminate the KVM process. | |
| Analizada | Crítica (9.3) | 0.51% | — | Jetkvm KVM | 17/3/2026 | 17/6/2026 | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. | |
| Analizada | Alta (7) | 0.10% | — | Jetkvm KVM | 17/3/2026 | 17/6/2026 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI | 2/10/2025 | 17/6/2026 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This… | |
| Aplazada | Baja (2.7) | 0.39% | — | Risc Zero Risc0 ZkvmAIRisc Zero Risc0 Circuit Rv32imAIRisc Zero Risc0 Circuit Rv32im SYSAI | 6/8/2025 | 17/6/2026 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed integer division allows… | |
| Aplazada | Baja (2.7) | 0.27% | — | Risc Zero Risc0 ZkvmAI | 20/6/2025 | 17/6/2026 | RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a malicious prover. The main idea for the… | |
| Aplazada | Alta (8.7) | 1.0% | — | Command Center LCD KVM Over IP Switch Cl5708imAI | 9/5/2025 | 17/6/2026 | The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to perform a denial-of-service attack. | |
| Modificada | Alta (8.8) | 0.38% | — | Kvmtool Project Kvmtool | 15/4/2023 | 17/6/2026 | kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute arbitrary code on the host machine. | |
| Modificada | Alta (7.5) | 0.41% | — | Cpplusworld Kvms PRO | 28/3/2023 | 17/6/2026 | CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected. | |
| Modificada | Crítica (9.8) | 17% | — | Asus Asmb8-ikvm Firmware | 26/2/2023 | 17/6/2026 | ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Alta (7.2) | 2.0% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. | |
| Modificada | Alta (7.2) | 2.0% | — | Asus Z10pr-d16 FirmwareAsus Asmb8-ikvm FirmwareAsus Z10pe-d16 WS Firmware | 6/4/2021 | 17/6/2026 | The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. |