Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 0.22% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot. | |
| Analizada | Crítica (9.5) | 0.35% | — | Ecovacs Deebot X2 Omni FirmwareEcovacs Deebot X2 Combo FirmwareEcovacs Deebot X2S FirmwareEcovacs Deebot X5 PRO Firmware+16 | 23/1/2025 | 17/6/2026 | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates. | |
| Analizada | Baja (1.8) | 0.21% | — | Ecovacs Deebot N8 FirmwareEcovacs Deebot 900 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on. | |
| Analizada | Media (4.8) | 0.15% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism. | |
| Analizada | Media (5.3) | 0.33% | — | Ecovacs Deebot N10 FirmwareEcovacs Deebot T10 FirmwareEcovacs Deebot X1 FirmwareEcovacs Deebot T20 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key. | |
| Analizada | Alta (7) | 0.40% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root. | |
| Analizada | Crítica (9.8) | 0.56% | — | ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+12 | 10/12/2024 | 17/6/2026 | Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2… | |
| Modificada | Alta (7.5) | 0.33% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | |
| Modificada | Crítica (9.8) | 0.88% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device. | |
| Modificada | Alta (8.8) | 2.1% | — | CBC Nr4h FirmwareCBC Nr8h FirmwareCBC Nr16h FirmwareCBC Dr-16f42a Firmware+19 | 23/8/2023 | 17/6/2026 | OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F,… | |
| Modificada | Alta (8.8) | 1.3% | — | CBC Nr4h FirmwareCBC Nr8h FirmwareCBC Nr16h FirmwareCBC Dr-16f42a Firmware+19 | 23/8/2023 | 17/6/2026 | Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F,… | |
| Modificada | Alta (8.8) | 1.1% | — | CBC Nr4h FirmwareCBC Nr8h FirmwareCBC Nr16h FirmwareCBC Dr-16f42a Firmware+19 | 23/8/2023 | 17/6/2026 | Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F,… | |
| Modificada | Alta (7.8) | 0.10% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC KIT Nuc7i7bnhx1 FirmwareIntel NUC 7 Home Nuc7i5bnkp FirmwareIntel NUC 7 Home Nuc7i3bnhxf FirmwareIntel NUC 7 Enthusiast Nuc7i7bnkq Firmware+19 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.17% | — | Intel NUC KIT Nuc6cayh FirmwareIntel NUC KIT Nuc6cays FirmwareIntel NUC Mini PC Nuc7i3bnhxf FirmwareIntel NUC Mini PC Nuc7i3bnk Firmware+63 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.14% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+55 | 10/5/2023 | 17/6/2026 | Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.8) | 0.32% | — | Moxa Uc-2101-lx FirmwareMoxa Uc-2102-lx FirmwareMoxa Uc-2102-t-lx FirmwareMoxa Uc-2104-lx Firmware+50 | 7/3/2023 | 17/6/2026 | An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new… | |
| Modificada | Alta (7.8) | 0.20% | — | Moxa Uc-2101-lx FirmwareMoxa Uc-2102-lx FirmwareMoxa Uc-2104-lx FirmwareMoxa Uc-2111-lx Firmware+60 | 28/11/2022 | 17/6/2026 | UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image:… | |
| Modificada | Crítica (9.8) | 1.6% | — | Phoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 FirmwarePhoenixcontact FC 350 PCI ETH Firmware+13 | 21/6/2022 | 17/6/2026 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | |
| Modificada | Alta (8) | 0.79% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. | |
| Modificada | Media (5.3) | 0.59% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. | |
| Modificada | Alta (7.8) | 0.24% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. | |
| Modificada | Media (6.8) | 0.23% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. | |
| Modificada | Media (5.3) | 0.74% | — | Lenovo A1 FirmwareLenovo T1 FirmwareLenovo X1 FirmwareLenovo T2 Firmware+1 | 18/5/2022 | 17/6/2026 | An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. |