Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration. | |
| Analizada | Media (5.1) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication. | |
| Analizada | Media (6.9) | 0.60% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition. | |
| Analizada | Alta (7.1) | 0.46% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet. | |
| Analizada | Alta (8.2) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack. | |
| Analizada | Media (6.9) | 0.40% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication. | |
| Analizada | Crítica (9.3) | 0.71% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Alta (8.7) | 0.65% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Media (6.8) | 0.33% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command. | |
| Analizada | Crítica (9.1) | 0.57% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command. | |
| Analizada | Alta (7.5) | 0.55% | — | Silextechnology Ds-600 Firmware | 15/4/2024 | 17/6/2026 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command. | |
| Modificada | Alta (7.4) | 1.4% | — | Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an Firmware | 9/5/2018 | 17/6/2026 | Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an FirmwareSilextechnology Geh-500 FirmwareSilextechnology Sx-500 Firmware | 9/5/2018 | 17/6/2026 | In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings. | |
| Modificada | Media (5) | 1.2% | — | Silex Sx-2000wg Firmware | 2/7/2014 | 17/6/2026 | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889. | |
| Modificada | Media (5) | 1.2% | — | Silex Sx-2000wg Firmware | 2/7/2014 | 17/6/2026 | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnerability than CVE-2014-3890. | |
| Modificada | Media (4.3) | 1.2% | — | Silexlabs Silex | 20/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |