Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.36% | — | Tp-link Tapo C200 Firmware | 24/6/2026 | 29/6/2026 | A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful… | |
| Pendiente de análisis | Media (5.1) | 0.20% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of… | |
| Pendiente de análisis | Alta (7.2) | 0.24% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. | |
| Analizada | Crítica (9.8) | 0.84% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. | |
| Analizada | Media (5.3) | 0.21% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.3) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0. | |
| Analizada | Media (4.6) | 0.39% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.1) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Alta (7.5) | 0.46% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerability in the device registration function. This vulnerability could allow an attacker to cause a denial of service attack on the remote target device. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Tl-wr940n Firmware | 17/6/2026 | 18/6/2026 | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges. | |
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Tl-wr940n Firmware | 17/6/2026 | 18/6/2026 | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges. | |
| Analizada | Alta (8.8) | 2.5% | ⚠ Explotación activa | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 16/6/2026 | 22/9/2026 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | |
| Analizada | Alta (7.4) | 0.58% | — | Dlink Dcs-935l Firmware | 13/6/2026 | 23/7/2026 | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly… | |
| Aplazada | Media (5.1) | 0.21% | — | Naxclow Device FirmwareAIRt-threadAI | 12/6/2026 | 17/6/2026 | During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary memory reads,… | |
| Pendiente de análisis | Alta (7) | 0.08% | — | Moxa Embedded Linux FirmwareAI | 12/6/2026 | 17/6/2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714.… | |
| Analizada | Alta (7) | 0.94% | — | Tp-link Tapo C110 Firmware | 11/6/2026 | 17/6/2026 | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote… | |
| Pendiente de análisis | Alta (8.4) | 0.08% | — | Lenovo Thinkpad Embedded Controller FirmwareAI | 10/6/2026 | 7/10/2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. | |
| Analizada | Media (6.9) | 0.68% | — | Netgear Mr70 FirmwareNetgear Ms70 FirmwareNetgear Raxe500 FirmwareNetgear Xr1000 Firmware | 9/6/2026 | 23/7/2026 | A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. |