Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | ZTE Zxv10 W300 FirmwareZTE Zxv10 W300 | 19/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1. | |
| Modificada | Alta (10) | 59% | 💥 Exploit | ZTE F460ZTE F660 | 11/3/2014 | 17/6/2026 | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials. | |
| Modificada | Alta (9.3) | 8.5% | 💥 Exploit | ZTE Zxv10 W300 | 4/2/2014 | 17/6/2026 | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password. | |
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Mw6tech Aztec Activex ControlMw6tech Datamatrix Activex ControlMw6tech Maxicode Activex Control | 21/1/2014 | 16/6/2026 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | ZTE Zxdsl | 31/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter. | |
| Modificada | Alta (10) | 3.6% | — | ZTE Score M | 29/5/2012 | 16/6/2026 | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application. | |
| Modificada | Alta (10) | 2.4% | — | Aztech Adsl2/2+4-port Router | 3/4/2009 | 16/6/2026 | Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if this default is not changed. | |
| Modificada | Alta (10) | 3.7% | — | Aztech Adsl2/2+4-port Router | 30/3/2009 | 16/6/2026 | cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. | |
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies Aztec Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Eztechhelp Ezcms | 30/6/2008 | 16/6/2026 | admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Eztechhelp Company Ezcms | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (9.3) | 6.0% | 💥 Exploit | Idautomation Aztec BarcodeIdautomation Datamatrix BarcodeIdautomation Linear BarcodeIdautomation Pdf417 Barcode | 18/5/2008 | 16/6/2026 | IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL… | |
| Modificada | Alta (9.3) | 1.8% | — | Aztech DSL 600eu Router | 6/9/2007 | 16/6/2026 | The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows remote attackers to connect to the web interface by guessing a TCP sequence number, possibly involving spoofing of an ARP packet, a related issue to CVE-1999-0077. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Aztek Forum | 30/1/2007 | 16/6/2026 | SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php. | |
| Modificada | Alta (7.5) | 1.6% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays. | |
| Modificada | Alta (7.5) | 1.6% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET,… | |
| Modificada | Media (6) | 1.1% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter. | |
| Modificada | Media (5) | 1.4% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Aztek Forum | 9/3/2006 | 16/6/2026 | Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Aztek Forum | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Aztek Forum | 9/3/2006 | 16/6/2026 | Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Aztek Forum | 7/3/2005 | 16/6/2026 | The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Aztek Forum | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Gaztek Ghttpd | 31/12/2002 | 16/6/2026 | Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Gaztek Ghttp | 6/12/2001 | 16/6/2026 | Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. |