Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1)0.14%—Silabs Series 2AI9/2/202617/6/2026
DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an attacker to eventually extract secret keys through a DPA attack.
AplazadaBaja (1)0.22%—Silabs Series 2AISilabs EcdhAISilabs EddsaAI29/4/202517/6/2026
DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The best practice is to use the impacted crypto…
AplazadaMedia (4.2)0.18%—Silabs Series 2AI17/3/202517/6/2026
The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.
ModificadaCrítica (9.1)5.8%—Schneider-electric SMT Series 1015 UPS FirmwareSchneider-electric SMC Series 1018 UPS FirmwareSchneider-electric Smtl Series 1026 UPS FirmwareSchneider-electric SCL Series 1029 UPS Firmware+299/3/202217/6/2026
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and…
ModificadaMedia (5.3)1.9%—Fanuc Series 30I FirmwareFanuc Series 31I FirmwareFanuc Series 32i-b Plus FirmwareFanuc Series 35i-b Firmware+123/8/202017/6/2026
A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices.