Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.79%—Contec Health Cms8000 Patient MonitorAI30/1/202517/6/2026
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle…
AplazadaCrítica (9.3)1.3%—Contec Health Cms8000AI30/1/202517/6/2026
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
AnalizadaAlta (8.1)0.16%—Huawei Pt9030-15 FirmwareHuawei Ws7206-10 FirmwareHuawei Ws7290-15 FirmwareHuawei Ws8000-10 Firmware+528/12/202417/6/2026
A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has been assigned a (CVE)ID:CVE-2023-52718
AnalizadaAlta (7.5)0.44%—Trianglemicroworks IEC 61850 Source Code LibrarySiemens Sicam A8000 FirmwareSiemens Sicam SCC FirmwareSiemens Sicam EGS Firmware+218/9/202417/6/2026
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.
ModificadaMedia (5.5)0.21%—Unisoc S8000Unisoc Sc7731eUnisoc Sc9832eUnisoc Sc9863a+912/7/202317/6/2026
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
ModificadaMedia (5.7)0.30%—Contechealth Cms8000 Firmware13/9/202217/6/2026
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or…
ModificadaMedia (4.4)0.19%—Contechealth Cms8000 Firmware13/9/202217/6/2026
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities.
ModificadaAlta (7.5)0.98%—Contechealth Cms8000 Firmware13/9/202217/6/2026
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass…
ModificadaMedia (6.1)0.32%—Contechealth Cms8000 Firmware13/9/202217/6/2026
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
ModificadaMedia (6.8)0.39%—Contechealth Cms8000 Firmware13/9/202217/6/2026
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load…
ModificadaCrítica (9.8)3.1%—Fujitsu Eternus Cs8000 Firmware20/6/202217/6/2026
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as…
ModificadaCrítica (9.8)3.1%—Fujitsu Eternus Cs8000 Firmware20/6/202217/6/2026
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or…
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.
ModificadaCrítica (9.8)2.2%—Siemens Ruggedcom ROS I800Siemens Ruggedcom ROS I801Siemens Ruggedcom ROS I802Siemens Ruggedcom ROS I803+4813/7/202117/6/2026
A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.7), RUGGEDCOM i801 (All versions < V4.3.7), RUGGEDCOM i802 (All versions < V4.3.7), RUGGEDCOM i803 (All versions < V4.3.7), RUGGEDCOM M2100 (All versions < V4.3.7), RUGGEDCOM M2200 (All versions < V4.3.7), RUGGEDCOM M969 (All versions <…
ModificadaAlta (8.1)0.81%—Huawei Secospace Antiddos8000 Firmware20/3/202017/6/2026
Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affected device. Due to the improper implementation of the authentication function, attackers can exploit the vulnerability to…
ModificadaAlta (7.5)0.97%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+223/1/202017/6/2026
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.
ModificadaMedia (5.5)0.20%—Huawei Ap2000 FirmwareHuawei IPS FirmwareHuawei Ngfw FirmwareHuawei Nip6300 Firmware+1313/12/201917/6/2026
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a buffer overflow vulnerability. An attacker who logs in to the board may send crafted…
ModificadaMedia (5.5)0.20%—Huawei Ap2000 FirmwareHuawei IPS FirmwareHuawei Ngfw FirmwareHuawei Nip6300 Firmware+1313/12/201917/6/2026
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace) have a resource management vulnerability. An attacker who logs in to the board may send crafted messages from the internal network.
ModificadaMedia (5.5)0.21%—Huawei Ap2000 FirmwareHuawei IPS FirmwareHuawei Ngfw FirmwareHuawei Nip6300 Firmware+1313/12/201917/6/2026
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a null pointer dereference vulnerability. The system dereferences a pointer that it expects to…
ModificadaMedia (5.5)0.20%—Huawei Ap2000 FirmwareHuawei IPS FirmwareHuawei Ngfw FirmwareHuawei Nip6300 Firmware+1313/12/201917/6/2026
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a DoS vulnerability. An attacker may send crafted messages from a FTP client to exploit this…
ModificadaAlta (8.6)0.74%—Huawei Ap2000 FirmwareHuawei IPS FirmwareHuawei Ngfw FirmwareHuawei Nip6300 Firmware+1313/12/201917/6/2026
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted…
ModificadaMedia (5.3)0.89%—Huawei Secospace Antiddos8000 Firmware15/2/201817/6/2026
Huawei Secospace AntiDDoS8000 V500R001C20SPC500 have a memory leak vulnerability due to memory don't be released when the system open some function. An attacker could exploit it to cause memory leak, which may further lead to system exceptions.
ModificadaCrítica (9.8)2.4%—Huawei Nip6300 FirmwareHuawei Secospace Usg6500 FirmwareHuawei Secospace Antiddos8000 FirmwareHuawei Usg9500 Firmware+523/5/201617/6/2026
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute…
Orbitaley — Vulnerabilidades