Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.25%—Moxa Uc-1222a FirmwareMoxa Uc-2222a-t-us FirmwareMoxa Uc-2222a-t FirmwareMoxa Uc-2222a-t-ap Firmware+315/2/202617/6/2026
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full…
AnalizadaAlta (7)0.14%—Moxa Uc-1222a FirmwareMoxa Uc-2222a-t-us FirmwareMoxa Uc-2222a-t FirmwareMoxa Uc-2222a-t-ap Firmware+315/2/202617/6/2026
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment…
ModificadaAlta (8.8)0.11%—Google Nest HUB MAX FirmwareGoogle Nest HUB FirmwareGoogle Wifi FirmwareGoogle Nest Wifi Point Firmware+125/7/202317/6/2026
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on…
ModificadaAlta (7.2)0.60%—Bbraun Battery-pack SP With Wifi Firmware13/3/202317/6/2026
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both the medical device WiFi network (such as…
ModificadaMedia (5.3)0.80%—Fresenius-kabi Agilia SP MC Wifi Firmware21/1/202217/6/2026
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
ModificadaAlta (8.8)4.3%—KPN Experia Wifi Firmware1/9/202117/6/2026
Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise user input to the syslog configuration form. An authenticated remote attacker could leverage this to alter the device configuration and achieve remote code execution. This can be exploited in…
ModificadaCrítica (9.8)37%—Velotismart Project Velotismart Wifi Firmware15/7/201817/6/2026
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.
ModificadaMedia (5)0.84%—Huawei WebuiHuawei E355s Mobile Wifi Firmware21/5/201517/6/2026
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands.
ModificadaAlta (9)1.1%—Huawei E587 Mobile Wifi Firmware21/5/201517/6/2026
Huawei E587 Mobile WiFi with firmware before 11.203.30.00.00 allows remote attackers to bypass authentication, change configurations, send messages, and cause a denial of service (device restart) via unspecified vectors.
ModificadaMedia (6.8)0.61%—Emobile Pocket Wifi FirmwareEmobile Pocket Wifi3/2/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.