Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.1) | 0.11% | — | Libx11AI | 28/9/2026 | 30/9/2026 | An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Libx11AI | 28/9/2026 | 30/9/2026 | An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Libx11AI | 28/9/2026 | 30/9/2026 | An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | |
| Pendiente de análisis | Alta (7.5) | 0.20% | — | Libx11AI | 21/9/2026 | 22/9/2026 | A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. | |
| Aplazada | Alta (8.1) | 0.27% | — | Hipase 250AIX11vncAI | 31/7/2026 | 28/8/2026 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected… | |
| Analizada | Crítica (9.8) | 3.8% | — | Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+159 | 20/1/2026 | 17/6/2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dpg-hgx2AISupermicro X11pdg-qtAISupermicro X11pdg-otAISupermicro X11pdg-snAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Supermicro BMC FirmwareAISupermicro X11AISupermicro X12AISupermicro H12AI+5 | 11/7/2024 | 17/6/2026 | An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC. | |
| Analizada | Alta (8.3) | 0.66% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows. | |
| Analizada | Alta (7.2) | 18% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges. | |
| Analizada | Alta (8.3) | 0.56% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.56% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.57% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Media (6.5) | 0.57% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.78% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Modificada | Alta (8.8) | 0.96% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.2% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi… | |
| Modificada | Alta (7.5) | 1.3% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information. | |
| Modificada | Alta (7.8) | 0.47% | — | X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora | 10/10/2023 | 17/6/2026 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. | |
| Modificada | Media (5.5) | 0.47% | — | X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora | 10/10/2023 | 17/6/2026 | A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. | |
| Modificada | Media (5.5) | 0.67% | — | X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora | 10/10/2023 | 17/6/2026 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system. | |
| Modificada | Alta (8) | 0.49% | — | Tp-link Archer Ax50 FirmwareTp-link Archer A10 FirmwareTp-link Archer Ax10 FirmwareTp-link Archer Ax11000 Firmware | 6/9/2023 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions… | |
| Modificada | Alta (7.8) | 0.39% | — | Supermicro X12dai-n6 FirmwareSupermicro X12ddw-a6 FirmwareSupermicro X12dgo-6 FirmwareSupermicro X12dgq-r Firmware+267 | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable. |