Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

309 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.95%—Weidmueller Uc20-wl2000-ac FirmwareWeidmueller Uc20-wl2000-iot FirmwareWeidmueller Iot-gw30 FirmwareWeidmueller Iot-gw30-4g-eu Firmware13/5/202117/6/2026
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.
ModificadaMedia (5.4)7.6%—Linux KernelDebian LinuxArista C-75 FirmwareArista O-90 Firmware+411/5/202117/6/2026
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or…
ModificadaMedia (5.3)5.6%—Samsung Galaxy I9305 FirmwareArista C-250 FirmwareArista C-260 FirmwareArista C-230 Firmware+1511/5/202117/6/2026
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP,…
ModificadaMedia (6.5)2.9%—Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+19011/5/202117/6/2026
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
ModificadaMedia (5.3)6.5%—NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+16211/5/202117/6/2026
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to…
ModificadaBaja (2.6)2.6%—Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+16411/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or…
ModificadaCrítica (9.8)1.7%—Dlink Dap-1880ac Firmware26/4/202117/6/2026
Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified vectors.
ModificadaAlta (8.8)2.4%—Dlink Dap-1880ac Firmware26/4/202117/6/2026
DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program.
ModificadaAlta (8.8)1.3%—Dlink Dap-1880ac Firmware26/4/202117/6/2026
Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to gain root privileges via unspecified vectors.
ModificadaAlta (8.8)1.7%—Dlink Dap-1880ac Firmware26/4/202117/6/2026
Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to bypass access restriction and to start a telnet service via unspecified vectors.
ModificadaAlta (8.8)2.3%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.
ModificadaAlta (8.8)1.3%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.
ModificadaAlta (8.8)2.1%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.
ModificadaAlta (7.5)6.4%💥 ExploitTotolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through…
ModificadaAlta (7.5)8.7%💥 ExploitTotolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,…
ModificadaCrítica (10)2.2%—Supermicro X11dai-n FirmwareSupermicro X11dac FirmwareSupermicro X11dph-tq FirmwareSupermicro X11dph-i Firmware+25921/9/201917/6/2026
On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the…
ModificadaCrítica (10)0.93%—Supermicro X11dai-n FirmwareSupermicro X11dac FirmwareSupermicro X11dph-tq FirmwareSupermicro X11dph-i Firmware+33221/9/201917/6/2026
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by…
ModificadaMedia (6.8)0.34%—Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+14419/8/201917/6/2026
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
ModificadaMedia (6.1)1.2%—Technicolor Tg789vac Firmware3/1/201917/6/2026
The admin web interface on Technicolor MediaAccess TG789vac v2 HP devices with firmware v16.3.7190-2761005-20161004084353 displays unsanitised user input, which allows an unauthenticated malicious user to embed JavaScript into the Log viewer interface via a crafted HTTP Referer header, aka XSS.
ModificadaAlta (7.5)32%—Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+476/9/201817/6/2026
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered…
ModificadaCrítica (9.8)74%💥 ExploitUI Airmax AC FirmwareUI Airmax M XM FirmwareUI Airmax M XW FirmwareUI Airmax M TI Firmware+85/9/201817/6/2026
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in…
ModificadaAlta (7.2)4.2%—Tp-link Er5110g FirmwareTp-link Er5120g FirmwareTp-link Er5510g FirmwareTp-link Er5520g Firmware+3411/1/201817/6/2026
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.
ModificadaAlta (7.2)4.2%—Tp-link Er5110g FirmwareTp-link Er5120g FirmwareTp-link Er5510g FirmwareTp-link Er5520g Firmware+3411/1/201817/6/2026
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file.
ModificadaAlta (7.2)4.4%—Tp-link Er5110g FirmwareTp-link Er5120g FirmwareTp-link Er5510g FirmwareTp-link Er5520g Firmware+3411/1/201817/6/2026
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.
ModificadaAlta (7.2)4.4%—Tp-link Er5110g FirmwareTp-link Er5120g FirmwareTp-link Er5510g FirmwareTp-link Er5520g Firmware+3411/1/201817/6/2026
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.