Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.26% | — | Darteweb Dimage 360 | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in D’arteweb DImage 360 allows Stored XSS.This issue affects DImage 360: from n/a through 2.0. | |
| Analizada | Alta (8.8) | 0.38% | — | Plugins360 All-in-one Video Gallery | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+237 | 3/6/2024 | 17/6/2026 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | |
| Analizada | Media (4.6) | 1.3% | — | Zohocorp Manageengine Pam360 | 29/5/2024 | 17/6/2026 | Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610. | |
| Aplazada | Media (6.5) | 0.39% | — | 360 V6GAI360 T5GAI360 T6MAI360 P1AI | 28/5/2024 | 17/6/2026 | An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Analizada | Alta (8.1) | 0.90% | — | Zohocorp Manageengine Pam360 | 20/5/2024 | 17/6/2026 | Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability. | |
| Aplazada | Media (5.3) | 0.44% | — | Wangshen Secgate 3600AI | 17/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+232 | 6/5/2024 | 17/6/2026 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+157 | 6/5/2024 | 17/6/2026 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | |
| Aplazada | Media (5.3) | 0.42% | — | Avirtum Ipanorama 360AI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1. | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 1.1% | — | Dlink Dap-2020 FirmwareDlink Dap-1360 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 Multiple Parameters Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 0.92% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of… | |
| Analizada | Alta (8.8) | 1.0% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc COMM_MakeCustomMsg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (8.8) | 1.1% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webupg UPGCGI_CheckAuth Numeric Truncation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 1.1% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc var:page Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 1.1% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc WEB_DisplayPage Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.5) | 0.91% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 1.0% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (8.8) | 0.93% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 1.2% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc WEB_DisplayPage Directory Traversal Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 1.2% | — | Dlink Dap-1360 FirmwareDlink Dap-2020 Firmware | 3/5/2024 | 17/6/2026 | D-Link DAP-1360 webproc var:menu Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Aplazada | Alta (8.8) | 1.6% | — | Plugins360 All-in-one Video GalleryAI | 2/5/2024 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with contributor access and… | |
| Aplazada | Media (6.1) | 0.61% | — | Dlink Dap-2230AIDlink Dap-2310AIDlink Dap-2330AIDlink Dap-2360AI+6 | 22/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component. | |
| Analizada | Media (6.1) | 0.27% | — | Asrmicro Asr3603 FirmwareAsrmicro Asr1607 FirmwareAsrmicro Asr1803sc FirmwareAsrmicro Asr3602 Firmware+9 | 16/4/2024 | 17/6/2026 | In huge memory get unmapped area check, code can never be reached because of a logical contradiction. |