Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.6) | 0.11% | — | Schneider-electric Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrative application privileges. | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands… | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user. | |
| Modificada | Media (6.3) | 0.68% | — | Cisco Firepower 9300 FirmwareCisco Firepower 4143 FirmwareCisco Firepower 4112 FirmwareCisco UCS 6324 Fabric Interconnect Firmware+4 | 23/8/2023 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected… | |
| Modificada | Media (6.7) | 0.34% | — | Cisco Firepower 4110 FirmwareCisco Firepower 4112 FirmwareCisco Firepower 4115 FirmwareCisco Firepower 4120 Firmware+8 | 25/8/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The attacker would need to have Administrator privileges on the device. This vulnerability is due to insufficient input validation of commands supplied by… | |
| Modificada | Alta (8.8) | 0.40% | — | Siemens Spectrum Power 4Siemens Spectrum Power 7Siemens Spectrum Power Microgrid Management System | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with… | |
| Modificada | Media (6.1) | 0.56% | — | Siemens Spectrum Power 4 | 9/2/2022 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP9 Security Patch 1). The integrated web application "Online Help" in affected product contains a Cross-Site Scripting (XSS) vulnerability that could be exploited if unsuspecting users are tricked into accessing a malicious link. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (5.3) | 0.90% | — | Siemens Spectrum Power 4 | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack. | |
| Modificada | Media (5.3) | 0.57% | — | Siemens Spectrum Power 4 | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names. | |
| Modificada | Alta (8.8) | 0.73% | — | Cisco Secure Firewall Threat DefenseCisco Firepower 9300 FirmwareCisco Firepower 4115 FirmwareCisco Firepower 4125 Firmware+5 | 2/10/2019 | 11/8/2026 | Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections… | |
| Modificada | Alta (8.2) | 0.78% | — | Cisco Secure Firewall Threat DefenseCisco Firepower 9300 FirmwareCisco Firepower 4115 FirmwareCisco Firepower 4125 Firmware+5 | 2/10/2019 | 11/8/2026 | Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections… | |
| Modificada | Media (6.1) | 0.79% | — | Siemens Spectrum Power 3Siemens Spectrum Power 4Siemens Spectrum Power 5Siemens Spectrum Power 7 | 11/7/2019 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web… | |
| Modificada | Media (6.7) | 0.61% | — | Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+23 | 13/5/2019 | 17/6/2026 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based… | |
| Modificada | Crítica (9.8) | 2.3% | — | Siemens Spectrum Power 4 | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or 443/TCP could execute system commands with administrative privileges. The security vulnerability could be exploited by an unauthenticated attacker with network access to… | |
| Modificada | Alta (7.8) | 77% | — | Cisco Unified Computing System Manager FirmwareCisco Firepower 9300 Security Appliance FirmwareCisco Firepower 4100 Next-generation Firewall Firmware | 2/11/2017 | 17/6/2026 | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to… |