Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.6)0.47%—Netgear Lbr1020 FirmwareNetgear Lbr20 FirmwareNetgear R6700ax FirmwareNetgear R7800 Firmware+189/6/202623/7/2026
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
AnalizadaMedia (5.2)0.39%—Netgear Cax30 FirmwareNetgear Rax30 FirmwareNetgear Rax5 FirmwareNetgear Raxe300 Firmware9/6/202623/7/2026
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
AnalizadaMedia (4.9)0.35%—Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+279/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.9)0.41%—Netgear Rbe970 FirmwareNetgear Rbe971 FirmwareNetgear Rbr860 FirmwareNetgear Rbre950 Firmware+49/6/202623/7/2026
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
AnalizadaMedia (4.6)0.14%—Netgear Rax120 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware9/6/202623/7/2026
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
AnalizadaMedia (4.4)0.29%—Netgear Jr6150 Firmware9/6/202623/7/2026
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR…
AnalizadaMedia (4.3)0.24%—Netgear Cbr750 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 FirmwareNetgear Mr60 Firmware+319/6/202623/7/2026
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
AnalizadaMedia (4.3)0.23%—Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+239/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
AnalizadaMedia (4.3)0.18%—Netgear Raxe450 FirmwareNetgear Raxe500 Firmware9/6/202623/7/2026
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or…
AnalizadaMedia (4.3)0.23%—Netgear Rbe970 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 FirmwareNetgear Rbr850 Firmware+99/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.3)0.17%—Netgear Rbe970 Firmware9/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.3)0.32%—Netgear Rbe370 FirmwareNetgear Rbe770 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 Firmware+109/6/202623/7/2026
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.3)0.15%—Netgear Jr6150 Firmware9/6/202623/7/2026
Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no…
AnalizadaMedia (4.2)0.28%—Netgear Rbe970 FirmwareNetgear Rbr350 FirmwareNetgear Rbr760 FirmwareNetgear Rbs350 Firmware+19/6/202623/7/2026
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this…
AnalizadaBaja (1.9)0.22%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+159/6/202623/7/2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
AnalizadaMedia (4.8)0.26%—Netgear Rbe370 FirmwareNetgear Rbe371 FirmwareNetgear Rbe372 FirmwareNetgear Rbe374 Firmware9/6/202623/7/2026
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
AnalizadaBaja (2.9)0.40%—Dlink Dgs-1100-08pd Firmware8/6/202623/7/2026
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The…
AnalizadaMedia (5.5)0.43%—Dlink Dcs-5615 Firmware8/6/202623/7/2026
A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the…
AnalizadaBaja (2.1)0.51%—Dlink Dir-823g Firmware8/6/202623/7/2026
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be…
AnalizadaAlta (7.1)0.33%—Tp-link Tapo C520ws Firmware5/6/202619/6/2026
A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input. Crafted inputs can trigger a processing error, causing the RTSP service to enter non-responsive state. Successful exploitation may cause the RTSP in a…
AnalizadaBaja (2.1)3.1%—Dlink Dwr-m920 Firmware5/6/202617/6/2026
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AnalizadaBaja (2.1)4.2%—Dlink Dwr-m920 Firmware5/6/202623/7/2026
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AnalizadaMedia (5.8)0.12%—Navtor Navbox Firmware4/6/202622/7/2026
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants…
AnalizadaMedia (6.9)0.31%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
AnalizadaAlta (8.8)0.44%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.