Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.4%—NEC Aterm Hc100rc Firmware9/1/201917/6/2026
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.
ModificadaAlta (7.2)1.4%—NEC Aterm Hc100rc Firmware9/1/201917/6/2026
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.
ModificadaAlta (7.2)1.4%—NEC Aterm Hc100rc Firmware9/1/201917/6/2026
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.
ModificadaAlta (7.2)1.4%—NEC Aterm Hc100rc Firmware9/1/201917/6/2026
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.
ModificadaAlta (7.2)1.4%—NEC Aterm Hc100rc Firmware9/1/201917/6/2026
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.
ModificadaMedia (6.1)0.83%—Actiontec C1000a Firmware6/12/201817/6/2026
Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C1000A router with firmware through CAC004-31.30L.95 allows a remote attacker to inject arbitrary HTML into the Website Blocking page by inserting arbitrary HTML into the 'TodUrlAdd' URL parameter in…
ModificadaMedia (4.9)1.3%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate users.
ModificadaMedia (6.5)1.0%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.
ModificadaAlta (8.8)2.5%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legitimate user downloads and executes the modified client from the affected device, then he/she could…
ModificadaCrítica (9.8)2.3%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device.
ModificadaCrítica (9.8)2.7%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is able to obtain certain knowledge specific to the attacked device.
ModificadaAlta (8.2)1.5%—Siemens Siclock Tc400 FirmwareSiemens Siclock Tc100 Firmware3/7/201817/6/2026
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to the device, causing potential reboots of the device. The core functionality of the device could be…
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
ModificadaCrítica (9.8)80%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
ModificadaCrítica (9.8)87%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
ModificadaCrítica (9.8)82%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
ModificadaAlta (7.5)1.8%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
ModificadaMedia (5.9)0.79%—Zyxel Nwa1100-n FirmwareZyxel Nwa1100-nh FirmwareZyxel Nwa1121-ni FirmwareZyxel Nwa1123-ac Firmware+2128/9/201717/6/2026
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business…
ModificadaAlta (10)5.6%—Honeywell Excel WEB XL 1000c100 104 I/OHoneywell Excel WEB XL 1000c1000 600 I/OHoneywell Excel WEB XL 1000c1000 600 I/O UuklHoneywell Excel WEB XL 1000c100u 104 I/O Uukl+431/3/201517/6/2026
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read…
ModificadaAlta (10)9.5%—Schneider-electric Stbnic2212 FirmwareSchneider-electric Stbnip2212 FirmwareSchneider-electric Tsxetc0101 FirmwareSchneider-electric Tsxetc100 Firmware+393/10/201417/6/2026
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7,…
ModificadaBaja (3.5)2.3%—HP 0150a129HP 0150a12aHP 0150a12bHP 0150a12c+6711/2/201316/6/2026
Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router,…
ModificadaAlta (10)3.3%—UTC Fire & Security Ge-mc100-ntp/gps-zb Master Clock Device23/2/201216/6/2026
The UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock device uses hardcoded credentials for an administrative account, which makes it easier for remote attackers to obtain access via an HTTP session.
ModificadaBaja (3.6)0.55%—HP Windows Event LOG SmartconnectorHP Arcsight C1000 ApplianceHP Arcsight C1300 ApplianceHP Arcsight C3200 Appliance+319/7/201116/6/2026
Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.
Orbitaley — Vulnerabilidades