Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.6)1.8%—Cisco Small Business RV Router FirmwareCisco Small Business RV Router Firmware 1.016/5/201717/6/2026
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability…
ModificadaMedia (5.8)1.6%—Cisco Small Business RV Series Router Firmware3/5/201717/6/2026
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request…
ModificadaAlta (8.8)3.7%💥 ExploitDigisol Dg-hr1400 Router Firmware14/3/201717/6/2026
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.
ModificadaAlta (7.5)1.1%—Huawei Ws331a Router Firmware21/9/201617/6/2026
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special packages" to the LAN interface.
ModificadaMedia (6.1)1.2%—Huawei Ws331a Router Firmware21/9/201617/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via unspecified vectors.
ModificadaAlta (8.8)3.7%—Cisco Rv180 VPN Router FirmwareCisco Rv180w VPN Router Firmware8/8/201617/6/2026
Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.
ModificadaAlta (7.5)7.4%—Cisco Rv180 VPN Router FirmwareCisco Rv180w Wireless-n Multifunction VPN Router Firmware8/8/201617/6/2026
Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.
ModificadaAlta (8.8)2.3%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware8/8/201617/6/2026
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.
ModificadaAlta (7.8)1.9%💥 ExploitCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware8/8/201617/6/2026
The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
ModificadaMedia (6.5)1.8%—Cisco Rv215w Wireless-n VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router Firmware19/6/201617/6/2026
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote authenticated users to cause a denial of service (device reload) via crafted configuration commands in…
ModificadaMedia (6.1)1.0%—Cisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv215w Wireless-n VPN Router Firmware19/6/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka…
ModificadaCrítica (9.8)4.8%—Cisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall Firmware19/6/201617/6/2026
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.
ModificadaCrítica (9.8)2.5%—Sixnet Bt-5 Series Cellular Router FirmwareSixnet Bt-6 Series Cellular Router Firmware31/5/201617/6/2026
Sixnet BT-5xxx and BT-6xxx M2M devices before 3.8.21 and 3.9.x before 3.9.8 have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors.
ModificadaCrítica (9.8)2.7%—Cisco RV Series Router FirmwareSUN Opensolaris27/1/201617/6/2026
SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.
ModificadaMedia (4.3)1.8%—Cisco Sa520Cisco Sa520wCisco Sa540Cisco Rv016 Multi-wan VPN Firmware+313/12/201517/6/2026
The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224.
ModificadaMedia (4.3)1.0%—Alcatel-lucent Cellpipe 7130 Router Firmware18/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.
ModificadaAlta (10)2.4%—Digicom Dg-5514t Adsl Router Firmware10/12/201417/6/2026
Digicom DG-5514T ADSL router with firmware 3.2 generates predictable session IDs, which allows remote attackers to gain administrator privileges via a brute force session hijacking attack.
ModificadaAlta (7.5)8.6%💥 ExploitTechnicolor Td5130 Router Firmware5/12/201417/6/2026
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).
ModificadaMedia (4.3)4.0%💥 ExploitTechnicolor Td5130 Router Firmware5/12/201417/6/2026
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.
ModificadaMedia (4.3)3.2%💥 ExploitTechnicolor Td5130 Router Firmware5/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.
ModificadaAlta (10)67%💥 ExploitBelkin N750 Wireless Router FirmwareBelkin N750 Wireless Router12/11/201417/6/2026
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.
ModificadaMedia (6.8)0.61%—Cisco Linksys Wrt310n Router FirmwareCisco Linksys Wrt350n29/9/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports.
ModificadaMedia (6.8)2.3%💥 ExploitBeetel 450tc2 Router FirmwareBeetel 450tc2 Router20/5/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to…
ModificadaAlta (9.3)4.2%—Dlink Dir-826l Wireless N600 Cloud Router FirmwareDlink Dir-826l Wireless N600 Cloud RouterDlink Dir-505l Shareport Mobile Companion FirmwareDlink Dir-505l Shareport Mobile Companion12/5/201416/6/2026
D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is active.
ModificadaMedia (4.3)0.93%—SFR BOX Router FirmwareSFR BOX Router9/3/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the SFR Box router with firmware NB6-MAIN-R3.3.4 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) dns, (2) dhcp, (3) nat, (4) route, or (5) lan in network/; or (6) wifi/config.