Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 16% | — | Netgear R6250 Firmware | 6/6/2023 | 9/7/2026 | There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges. | |
| Modificada | Media (6.1) | 0.80% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Netgear SRX5308 up to 4.3.5-3. This vulnerability affects unknown code of the component Web Management Interface. The manipulation of the argument USERDBUsers.Password leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.80% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Management Interface. The manipulation of the argument Login.userAgent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument wanName leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument ConfigPort.LogicalIfName leads to… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been classified as problematic. Affected is an unknown function of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ManualDate.minutes leads to cross site scripting. It is… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. This issue affects some unknown processing of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ntp.server2 leads to cross site scripting. The attack may… | |
| Modificada | Media (4.8) | 0.66% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability has been found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. This vulnerability affects unknown code of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ntp.server1 leads to cross site scripting. The attack… | |
| Modificada | Media (4.8) | 0.66% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.emailServer leads to cross site scripting.… | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Netgear SRX5308 up to 4.3.5-3. Affected by this issue is some unknown functionality of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.fromAddr… | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Netgear SRX5308 up to 4.3.5-3. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument winsServer1 leads to cross site scripting.… | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.toAddr leads to cross site scripting. It is… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been rated as problematic. This issue affects some unknown processing of the file scgi-bin/platform.cgi?page=ike_policies.htm of the component Web Management Interface. The manipulation of the argument IpsecIKEPolicy.IKEPolicyName leads to cross site… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been declared as problematic. This vulnerability affects unknown code of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument dhcp.SecDnsIPByte2 leads to cross site scripting. The… | |
| Modificada | Media (4.8) | 0.66% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been classified as problematic. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.fromAddr leads to cross site scripting.… | |
| Modificada | Media (4.8) | 0.65% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability was found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. Affected by this issue is some unknown functionality of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument sysLogInfo.serverName leads to cross… | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability has been found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=bandwidth_profile.htm of the component Web Management Interface. The manipulation of the argument BandWidthProfile.ProfileName… | |
| Modificada | Media (6.5) | 1.3% | — | Netgear Srx5308 Firmware | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier… | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear R6900 FirmwareNetgear R6700 Firmware | 26/4/2023 | 17/6/2026 | Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page. | |
| Modificada | Alta (8) | 1.5% | — | Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+29 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling… | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+20 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled… | |
| Modificada | Alta (8.8) | 1.3% | — | Netgear Lax20 FirmwareNetgear R6400 FirmwareNetgear R6700 FirmwareNetgear R7000 Firmware+19 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing… | |
| Modificada | Alta (8.8) | 0.34% | — | Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+20 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue… | |
| Modificada | Alta (8.8) | 25% | — | Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+23 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the… | |
| Modificada | Alta (8.8) | 0.88% | — | Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+29 | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic… |