Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
309 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.44% | — | UI Airfiber Gigabeam FirmwareUI Airfiber 60-xg FirmwareUI Airfiber 60-hd FirmwareUI Airfiber 60-lr Firmware+2 | 23/12/2022 | 17/6/2026 | An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device. | |
| Modificada | Media (6.1) | 0.47% | — | Weidmueller 19 IOT Md01 LAN H4 S0011 FirmwareWeidmueller FP IOT Md01 4EU S2 00000 FirmwareWeidmueller FP IOT Md01 LAN S2 00000 FirmwareWeidmueller FP IOT Md01 LAN S2 00011 Firmware+5 | 14/12/2022 | 17/6/2026 | Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected… | |
| Modificada | Crítica (9.8) | 1.0% | — | Neoinfosys Nis-hap11ac Firmware | 19/9/2022 | 17/6/2026 | This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device. | |
| Modificada | Crítica (9.8) | 34% | 💥 PoC | Draytek Vigor3910 FirmwareDraytek Vigor1000b FirmwareDraytek Vigor2962 FirmwareDraytek Vigor2962p Firmware+64 | 29/8/2022 | 17/6/2026 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field. | |
| Modificada | Alta (7.8) | 0.18% | — | Emerson Controlwave PAC FirmwareEmerson Controlwave Micro Firmware | 17/8/2022 | 17/6/2026 | The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in… | |
| Modificada | Media (4.8) | 0.96% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+86 | 10/8/2022 | 17/6/2026 | Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS. | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance W700 Ieee 802.11ax FirmwareSiemens Scalance W700 Ieee 802.11n Firmware+80 | 10/8/2022 | 17/6/2026 | Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack. | |
| Modificada | Alta (7.2) | 1.8% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+86 | 10/8/2022 | 17/6/2026 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. | |
| Modificada | Crítica (9.8) | 0.63% | — | Allnet All-wr0500ac Firmware | 21/7/2022 | 17/6/2026 | Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly. | |
| Modificada | Crítica (9.8) | 1.3% | — | Nexans Gigaswitch 641 Desk V5 Sfp-vi FirmwareNexans Gigaswitch 642 Desk V5 Sfp-2vi FirmwareNexans Gigaswitch V5 2tp(pd-f+) Sfp-vi 54vdc FirmwareNexans Gigaswitch V5 2tp(pse+) Sfp-vi 54vdc Firmware+9 | 17/7/2022 | 17/6/2026 | libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Alta (7.8) | 4.8% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00… | |
| Modificada | Alta (7.8) | 6.2% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions… | |
| Modificada | Media (6.1) | 0.73% | — | Netgear Wac120 AC Firmware | 4/3/2022 | 17/6/2026 | Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking. | |
| Modificada | Crítica (9.8) | 13% | — | Tp-link Tl-wr902ac Firmware | 24/2/2022 | 17/6/2026 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.68% | — | Commscope Arris Surfboard Sbg6950ac2 FirmwareCommscope Arris Surfboard Sbg7400ac2 FirmwareCommscope Arris Surfboard Sbg7580ac FirmwareCommscope Arris Surfboard Sbg7600ac2 Firmware+1 | 15/2/2022 | 17/6/2026 | CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. | |
| Modificada | Alta (7.5) | 0.96% | — | Ruijie Rg-uac Firmware | 16/11/2021 | 17/6/2026 | Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco Aironet 1542d FirmwareCisco Aironet 1562d FirmwareCisco Aironet 1815m FirmwareCisco Aironet 1830e Firmware+37 | 23/9/2021 | 17/6/2026 | A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A… | |
| Modificada | Media (6.5) | 0.81% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two… | |
| Modificada | Alta (7.5) | 0.96% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key. | |
| Modificada | Alta (7.5) | 0.96% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi via a do_graph_auth action without a session_id key. | |
| Modificada | Alta (7.5) | 0.96% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with an unknown action name. | |
| Modificada | Alta (7.5) | 0.96% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to apply_cgi via action do_graph_auth without login_name key. | |
| Modificada | Alta (7.5) | 0.96% | — | Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware | 10/8/2021 | 17/6/2026 | Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a POST request to apply_cgi via an action ping_test without a ping_ipaddr key. | |
| Modificada | Alta (7.3) | 0.72% | — | Phoenixcontact AXL F BK PN TPS XC FirmwarePhoenixcontact AXL F BK PN TPS FirmwarePhoenixcontact AXL F BK EIP FirmwarePhoenixcontact AXL F BK EIP EF Firmware+14 | 25/6/2021 | 17/6/2026 | In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists. |