Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 5.3% | — | FS S3900 24t4s Firmware | 29/5/2023 | 17/6/2026 | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | |
| Modificada | Alta (8.8) | 0.97% | — | FS S3900 24t4s Firmware | 22/10/2020 | 17/6/2026 | An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges. | |
| Modificada | Alta (7.5) | 0.96% | — | Huawei Dbs3900 TDD LTE FirmwareHuawei Dp300 FirmwareHuawei Rp200 FirmwareHuawei Te30 Firmware+3 | 21/1/2020 | 17/6/2026 | There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash. | |
| Modificada | Alta (7.5) | 0.96% | — | Huawei Dbs3900 TDD LTE FirmwareHuawei Dp300 FirmwareHuawei Rp200 FirmwareHuawei Te30 Firmware+3 | 21/1/2020 | 17/6/2026 | There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash. | |
| Modificada | Media (4.3) | 0.44% | — | Huawei Dbs3900 TDD LTE Firmware | 23/3/2018 | 17/6/2026 | DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an insecure encryption algorithm is negotiated in the communication, an unauthenticated remote attacker can exploit this… | |
| Modificada | Alta (7.5) | 0.94% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack. | |
| Modificada | Alta (10) | 1.7% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers… | |
| Modificada | Alta (9.3) | 2.3% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI. |