Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.54% | — | Loytec LIP Me201cAILoytec L INXAILoytec L GateAILoytec L ROCAI+4 | 24/7/2026 | 27/7/2026 | Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet… | |
| Aplazada | Media (6.6) | 0.54% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID… | |
| Aplazada | Baja (3.8) | 0.16% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+4 | 24/7/2026 | 27/7/2026 | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long… | |
| Aplazada | Alta (8.4) | 0.19% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field. | |
| Aplazada | Crítica (9.2) | 0.18% | — | Loytec L-inxAILoytec L-gateAILoytec L-rocAILoytec L-iobAI+3 | 24/7/2026 | 27/7/2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on… | |
| Aplazada | Alta (8.4) | 0.15% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand. | |
| Aplazada | Alta (8.7) | 0.61% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+4 | 24/7/2026 | 27/7/2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft,… | |
| Aplazada | Baja (2) | 0.07% | — | Paddlepaddle FastdeployAI | 4/6/2026 | 22/7/2026 | A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is… | |
| Analizada | Alta (7.5) | 0.56% | — | Paddlepaddle | 23/3/2024 | 17/6/2026 | paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. | |
| Analizada | Crítica (9.1) | 1.1% | — | Paddlepaddle | 7/3/2024 | 17/6/2026 | Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6 | |
| Analizada | Crítica (9.8) | 1.7% | — | Paddlepaddle | 7/3/2024 | 17/6/2026 | remote code execution in paddlepaddle/paddle 2.6.0 | |
| Analizada | Alta (8.8) | 1.1% | — | Paddlepaddle | 7/3/2024 | 17/6/2026 | Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0 | |
| Analizada | Alta (7.8) | 1.2% | — | Paddlepaddle | 7/3/2024 | 17/6/2026 | Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 | |
| Modificada | Alta (7.8) | 0.46% | — | Paddlepaddle Paddle | 20/1/2024 | 17/6/2026 | Code Injection in paddlepaddle/paddle | |
| Modificada | Crítica (9.8) | 1.2% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system. | |
| Modificada | Alta (7.5) | 0.49% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Alta (7.5) | 0.49% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Crítica (9.8) | 1.2% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system. | |
| Modificada | Crítica (9.8) | 1.2% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system. | |
| Modificada | Crítica (9.8) | 0.54% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible. | |
| Modificada | Alta (7.5) | 0.49% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Crítica (9.8) | 0.53% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage. | |
| Modificada | Alta (7.5) | 0.49% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Alta (7.5) | 0.49% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Crítica (9.8) | 0.58% | — | Paddlepaddle | 3/1/2024 | 17/6/2026 | Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage. |