Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.78% | — | Tenda I6 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC9 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC9 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2pListFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 10/4/2026 | 17/6/2026 | A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.78% | — | Tenda Ch22 Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.78% | — | Tenda I12 Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.78% | — | Tenda I3 Firmware | 9/4/2026 | 17/6/2026 | A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda Ac15 Firmware | 9/4/2026 | 24/7/2026 | A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Crítica (9.8) | 0.39% | — | Tenda AC6 Firmware | 8/4/2026 | 25/7/2026 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters. | |
| Aplazada | Media (5.4) | 0.29% | — | Sukimalab Attendance ManagerAI | 8/4/2026 | 24/7/2026 | The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all versions up to, and including, 0.6.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda Cx12l Firmware | 6/4/2026 | 24/7/2026 | A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda Cx12l Firmware | 6/4/2026 | 24/7/2026 | A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda Cx12l Firmware | 6/4/2026 | 24/7/2026 | A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.3) | 0.69% | — | Tenda Cx12l Firmware | 6/4/2026 | 24/7/2026 | A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack requires access to the local network. The exploit has… | |
| Analizada | Baja (2) | 0.63% | — | Tenda Cx12l Firmware | 6/4/2026 | 24/7/2026 | A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack must originate from the local network. The exploit has been made… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda I12 Firmware | 6/4/2026 | 24/7/2026 | A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda Ch22 Firmware | 6/4/2026 | 24/7/2026 | A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda Ch22 Firmware | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda M3 Firmware | 5/4/2026 | 24/7/2026 | A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been… | |
| Analizada | Alta (8.7) | 0.95% | — | Tenda Ac10 Firmware | 5/4/2026 | 24/7/2026 | A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected. |