Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.57% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal… | |
| Aplazada | Alta (7.5) | 1.2% | 💥 PoC | RemixAIReact RouterAI | 1/4/2025 | 17/6/2026 | React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by… | |
| Analizada | Media (5.1) | 1.2% | — | Qnap Qurouter | 7/3/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later | |
| Analizada | Alta (7.7) | 1.1% | — | Qnap Qurouter | 7/3/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later | |
| Aplazada | Media (4.3) | 0.69% | 💥 PoC | DZS Router WEB InterfaceAI | 4/3/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the… | |
| Aplazada | Media (5.4) | 0.18% | — | Ixon Ixrouter Ix2400AI | 14/2/2025 | 17/6/2026 | IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically proximate attackers to gain root access via UART or SSH. | |
| Analizada | Media (5.4) | 0.79% | 💥 PoC | Mikrotik Routeros | 11/2/2025 | 17/6/2026 | An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username… | |
| Aplazada | Alta (8.4) | 0.19% | — | Billion Electric RouterAI | 11/2/2025 | 17/6/2026 | Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system. | |
| Aplazada | Alta (8.1) | 0.50% | — | SAP ApprouterAI | 11/2/2025 | 17/6/2026 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application | |
| Aplazada | Alta (8.6) | 0.44% | — | CP Plus RouterAI | 20/1/2025 | 17/6/2026 | This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the… | |
| Aplazada | Baja (2.7) | 6.4% | 💥 Exploit | Netis Wifi6 Router Nx10AINetis Wifi 11ac Router Nc65AINetis Wifi 11ac Router Nc63AINetis Wifi 11ac Router Nc21AI+1 | 6/1/2025 | 17/6/2026 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to… | |
| Aplazada | Crítica (9.3) | 1.8% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s… | |
| Aplazada | Alta (8.6) | 1.2% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. | |
| Aplazada | Alta (7.2) | 0.98% | — | Asus RouterAI | 2/1/2025 | 17/6/2026 | An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | |
| Aplazada | Media (5.9) | 0.50% | — | Sharp RouterAI | 23/12/2024 | 17/6/2026 | Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a remote unauthenticated attacker. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Sharp RouterAI | 23/12/2024 | 17/6/2026 | Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker. | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and… | |
| Analizada | Crítica (9.5) | 0.83% | — | Qnap Qurouter | 6/12/2024 | 17/6/2026 | A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later | |
| Analizada | Alta (8.1) | 0.65% | — | Synology Router Manager | 4/12/2024 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors. |