Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.7% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data. | |
| Modificada | Baja (3.3) | 4.1% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd. | |
| Modificada | Baja (2.9) | 3.8% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp. | |
| Modificada | Media (5.4) | 2.1% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter. | |
| Modificada | Media (5.8) | 3.3% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session. | |
| Modificada | Baja (3.3) | 2.6% | 💥 Exploit | Hotbox Router FirmwareHotbox Router | 30/12/2013 | 16/6/2026 | The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages. | |
| Modificada | Media (6.8) | 1.3% | — | Draytek Vigor 2700 Router FirmwareDraytek Vigor 2700 Router | 22/10/2013 | 16/6/2026 | The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Verizon Fios Actiontec Mi424wr-gen31 Router FirmwareVerizon Fios Actiontec Mi424wr-gen31 Router | 21/3/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2)… | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+14 | 13/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,… | |
| Modificada | Alta (7.5) | 1.3% | — | Technicolor Tg585 Router FirmwareTechnicolor Tg585 Router | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation on the Thomson (aka Technicolor) TG585 with firmware 7.x before 7.4.3.2 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Alcatel Speedtouch 5X6 Router FirmwareAlcatel Speedtouch 5X6 Router | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability. | |
| Modificada | Alta (10) | 5.5% | — | Edimax Br-6104k Router FirmwareEdimax Br-6104kCanyon-tech Cn-wf512 Router FirmwareCanyon-tech Cn-wf514 Router Firmware+8 | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary… | |
| Modificada | Alta (10) | 4.2% | — | Edimax Br-6104k Router FirmwareEdimax Br-6104kCanyon-tech Cn-wf512 Router FirmwareCanyon-tech Cn-wf514 Router Firmware+8 | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to establish… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Linksys Wrt54gx Router FirmwareLinksys Wrt54gx | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Linksys Wrt54g Router FirmwareLinksys Wrt54gCisco Linksys Wrt54gs Router FirmwareLinksys Wrt54gs | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP… | |
| Modificada | Alta (7.8) | 2.2% | — | Cisco Linksys Wrt54gc RouterCisco Linksys Wrt54gc Router Firmware | 24/1/2011 | 16/6/2026 | Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request. | |
| Modificada | Alta (7.5) | 1.5% | — | Sitecom Wl-153 Router FirmwareSitecom Wl-153 | 24/5/2006 | 16/6/2026 | Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 1.7% | — | X-micro Wlan 11B Broadband Router Firmware | 10/4/2004 | 16/6/2026 | X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access. | |
| Modificada | Alta (7.5) | 2.4% | — | X-micro Wlan 11B Broadband Router Firmware | 10/4/2004 | 16/6/2026 | X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access. | |
| Modificada | Media (5) | 2.2% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization. | |
| Modificada | Media (5) | 3.3% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface. | |
| Modificada | Media (5) | 2.0% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers. | |
| Modificada | Media (5) | 1.9% | — | Cisco SN 5420 Storage Router Firmware | 11/7/2001 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023. | |
| Modificada | Media (4.6) | 0.49% | — | Cisco SN 5420 Storage Router Firmware | 8/1/2001 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. |