Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.9% | 💥 Exploit | Netgear R6850 Firmware | 3/4/2024 | 17/6/2026 | An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required. | |
| Analizada | Crítica (9.8) | 47% | 💥 Exploit | Netgear R6850 Firmware | 3/4/2024 | 17/6/2026 | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. | |
| Analizada | Alta (8.8) | 0.32% | — | Netgear Dgnd4000 Firmware | 14/3/2024 | 17/6/2026 | An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component. | |
| Analizada | Alta (7.5) | 0.64% | — | Netgear Cbk40 FirmwareNetgear Cbk43 FirmwareNetgear Cbr40 Firmware | 12/3/2024 | 17/6/2026 | An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required. | |
| Analizada | Media (5.4) | 0.43% | — | Netgear Cbk40 FirmwareNetgear Cbr40 FirmwareNetgear Cbk43 Firmware | 12/3/2024 | 17/6/2026 | An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required. | |
| Modificada | Alta (8.8) | 19% | — | Netgear Rax30 Firmware | 7/3/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.53% | — | Netgear R7000 Firmware | 11/2/2024 | 17/6/2026 | A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.3) | 0.63% | — | Netgear R7000 Firmware | 11/2/2024 | 17/6/2026 | A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 4.0% | — | Netgear Wnr2000 Firmware | 15/12/2023 | 17/6/2026 | A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. | |
| Modificada | Crítica (9.8) | 9.0% | — | Netgear Rbr750 Firmware | 8/12/2023 | 17/6/2026 | In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. | |
| Modificada | Alta (7.8) | 0.54% | — | Netgear Prosafe Network Management System | 29/11/2023 | 17/6/2026 | A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM. | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear Prosafe Network Management System | 29/11/2023 | 17/6/2026 | NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear Cbr40 FirmwareNetgear Lax20 FirmwareNetgear Mk62 FirmwareNetgear Mr60 Firmware+11 | 1/9/2023 | 17/6/2026 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. | |
| Modificada | Alta (8.8) | 1.1% | — | Netgear Jwnr2000v2 FirmwareNetgear Xwn5001 FirmwareNetgear Xavn2001v2 Firmware | 7/8/2023 | 17/6/2026 | Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function. | |
| Modificada | Crítica (9.8) | 1.5% | — | Netgear R7100lg Firmware | 7/8/2023 | 17/6/2026 | Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. | |
| Modificada | Alta (8.8) | 0.96% | — | Netgear Ex6200 Firmware | 7/8/2023 | 17/6/2026 | Netgear EX6200 v1.0.3.94 was discovered to contain a buffer overflow via the wla_temp_ssid parameter at acosNvramConfig_set. | |
| Modificada | Alta (8.8) | 15% | — | Netgear Dc112a FirmwareNetgear Ex6200 FirmwareNetgear R6300v2 Firmware | 7/8/2023 | 17/6/2026 | Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi. | |
| Modificada | Media (6.5) | 0.68% | — | Netgear Dgn3500 Firmware | 7/8/2023 | 17/6/2026 | Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi. | |
| Modificada | Alta (8.8) | 0.76% | — | Netgear Jwnr2000v2 FirmwareNetgear Xwn5001 FirmwareNetgear Xavn2001v2 Firmware | 7/8/2023 | 17/6/2026 | Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function. | |
| Modificada | Alta (8.8) | 1.6% | — | Netgear Wg302v2 FirmwareNetgear Wag302v2 Firmware | 7/8/2023 | 17/6/2026 | Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters. | |
| Modificada | Alta (8.8) | 0.96% | — | Netgear Dg834gv5 Firmware | 7/8/2023 | 17/6/2026 | Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi. | |
| Modificada | Alta (8.8) | 0.96% | — | Netgear R6900p Firmware | 7/8/2023 | 17/6/2026 | Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi. | |
| Modificada | Alta (8.8) | 0.96% | — | Netgear Xr300 Firmware | 7/8/2023 | 17/6/2026 | Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi. | |
| Modificada | Crítica (9.8) | 14% | — | Netgear R6250 Firmware | 20/6/2023 | 17/6/2026 | netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. | |
| Modificada | Alta (8.8) | 3.1% | — | Netgear D6220 FirmwareNetgear D8500 FirmwareNetgear R6700 FirmwareNetgear R6900 Firmware | 6/6/2023 | 17/6/2026 | Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining… |