Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.91% | — | Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+22 | 11/8/2026 | 9/9/2026 | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. | |
| Analizada | Media (4.3) | 0.27% | — | Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+22 | 11/8/2026 | 9/9/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |
| Modificada | Alta (7.4) | 0.30% | — | Sick Lms531 FirmwareSick Lms511 FirmwareSick Lms500 Firmware | 24/8/2023 | 17/6/2026 | A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this… | |
| Modificada | Alta (8.8) | 0.95% | — | Sick Lms531 FirmwareSick Lms511 FirmwareSick Lms500 Firmware | 24/8/2023 | 17/6/2026 | The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device. | |
| Modificada | Alta (7.5) | 0.84% | — | Sick Lms531 FirmwareSick Lms511 FirmwareSick Lms500 Firmware | 24/8/2023 | 17/6/2026 | A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to… | |
| Modificada | Alta (7.5) | 0.42% | — | Sick Lms531 FirmwareSick Lms511 FirmwareSick Lms500 Firmware | 24/8/2023 | 17/6/2026 | The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password. | |
| Modificada | Crítica (9.8) | 0.87% | — | Bg-tek Coslat Bx5s1d3 FirmwareBg-tek Coslat Bx5s1d4 FirmwareBg-tek Coslat Bx5s1d5 FirmwareBg-tek Coslat Rm1ds1000 Firmware+4 | 24/2/2023 | 17/6/2026 | Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727. | |
| Modificada | Alta (7.5) | 1.4% | — | Sick Lms111 FirmwareSick Lms511 FirmwareSick Clv620 FirmwareSick Clv622 Firmware+26 | 31/8/2020 | 17/6/2026 | Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH. | |
| Modificada | Media (6.8) | 0.52% | — | Lenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 510s-08ish FirmwareLenovo Ideacentre 700 Firmware+107 | 10/8/2017 | 17/6/2026 | A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to… |