Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.24%—Kiloview P1 FirmwareKiloview P2 Firmware2/7/202417/6/2026
A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in…
ModificadaCrítica (9.8)0.42%—Kiloview P2 FirmwareKiloview P1 Firmware2/7/202417/6/2026
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
ModificadaAlta (8.8)0.37%—Fujitsu Si-r 30B FirmwareFujitsu Si-r 130b FirmwareFujitsu Si-r 90brin FirmwareFujitsu Si-r570b Firmware+1226/7/202317/6/2026
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions,…
ModificadaMedia (5.5)0.23%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
ModificadaMedia (6.7)0.29%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaCrítica (9.8)2.3%—VR CAM P1 Firmware15/9/202017/6/2026
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
ModificadaAlta (7.8)0.51%—Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+10822/7/202017/6/2026
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
ModificadaMedia (6)0.55%—Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+12922/7/202017/6/2026
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
ModificadaMedia (6.7)0.33%—Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
ModificadaMedia (6.8)0.28%—Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+969/6/202017/6/2026
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaAlta (8.8)1.8%—360 Safe Router P0 Firmware360 Safe Router P1 Firmware360 Safe Router P2 Firmware360 Safe Router P3 Firmware+14/11/201917/6/2026
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
ModificadaAlta (7.5)1.1%—Honeywell H4d8pr1 FirmwareHoneywell Hfd5pr1 FirmwareHoneywell Hpw2p1 FirmwareHoneywell Hdzp304di Firmware+4431/10/201917/6/2026
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
ModificadaAlta (7.5)2.1%—Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+2131/10/201917/6/2026
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
ModificadaCrítica (9.8)1.4%—Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+6031/10/201917/6/2026
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
ModificadaMedia (5.3)1.8%—Honeywell Hbd3pr2 FirmwareHoneywell H4d3prv3 FirmwareHoneywell Hed3pr3 FirmwareHoneywell H4d3prv2 Firmware+5526/9/201917/6/2026
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance…
ModificadaMedia (6.1)0.85%—Annke SP1 Firmware7/8/201917/6/2026
ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.
ModificadaCrítica (9.1)2.3%—Leagoo P1 Firmware25/4/201917/6/2026
The Leagoo P1 device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.wtk.factory (versionCode=1, versionName=1.0) that contains an exported broadcast receiver named com.wtk.factory.MMITestReceiver…
ModificadaMedia (5.5)0.39%—Leagoo P1 Firmware25/4/201917/6/2026
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains the android framework (i.e., system_server) with a package name of android that has been modified by Leagoo or another entity in the supply chain. The system_server process in…
ModificadaAlta (7.8)0.40%—Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+5524/1/201917/6/2026
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
ModificadaMedia (6.8)0.73%—Leagoo P1 Firmware28/12/201817/6/2026
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to…
ModificadaMedia (6.8)0.66%—Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+418/2/201817/6/2026
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.