Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.20%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver16/5/202417/6/2026
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaAlta (8.4)0.21%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)0.21%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)0.21%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)0.20%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.3)0.55%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
AnalizadaAlta (7.2)0.20%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6)0.23%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable denial of service via local access.
AnalizadaAlta (8.6)0.77%—Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver23/2/202417/6/2026
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaAlta (7.5)1.2%—MI Dgnwg03lm FirmwareMI Zncz03lm FirmwareMI Mccgq01lm FirmwareMI Rtcgq01lm Firmware20/12/201917/6/2026
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
ModificadaAlta (7.5)1.3%—MI Dgnwg03lm FirmwareMI Zncz03lm FirmwareMI Mccgq01lm FirmwareMI Wsdcgq01lm Firmware+120/12/201917/6/2026
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
ModificadaCrítica (9.8)1.3%—MI Dgnwg03lm FirmwareMI Zncz03lm FirmwareMI Mccgq01lm FirmwareMI Wsdcgq01lm Firmware+120/12/201917/6/2026
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
ModificadaMedia (6.8)0.34%—Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+14419/8/201917/6/2026
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
ModificadaAlta (7.8)2.4%—Tp-link Tl-sc3130Tp-link Tl-sc3130gTp-link Tl-sc3171Tp-link Tl-sc3171g+111/10/201316/6/2026
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the firmware revision via a "preset" action.
ModificadaAlta (7.1)3.5%—Tp-link Tl-sc3130Tp-link Tl-sc3130gTp-link Tl-sc3171Tp-link Tl-sc3171g+111/10/201316/6/2026
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd…
ModificadaAlta (10)3.7%—Tp-link Tl-sc3130Tp-link Tl-sc3130gTp-link Tl-sc3171Tp-link Tl-sc3171g+111/10/201316/6/2026
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.
ModificadaAlta (10)74%—Tp-link Tl-sc3130Tp-link Tl-sc3130gTp-link Tl-sc3171Tp-link Tl-sc3171g+111/10/201316/6/2026
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
ModificadaAlta (7.1)1.3%—Tp-link Tl-sc3130Tp-link Tl-sc3130gTp-link Tl-sc3171Tp-link Tl-sc3171g+11/10/201316/6/2026
The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not properly restrict access to certain administrative functions, which allows remote attackers to (1) cause a denial of service (device reboot) via a request to cgi-bin/reboot…