Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%—Zyxel Gs1900-10hp Firmware3/3/201617/6/2026
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.
ModificadaAlta (7.5)3.9%—Cisco Unified Computing SystemCisco Nx-osNetgear Jr6150 FirmwareSamsung X14j Firmware+33/3/201617/6/2026
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.
ModificadaCrítica (9.8)3.7%—Samsung X14j FirmwareSUN OpensolarisZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware3/3/201617/6/2026
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
ModificadaMedia (5.3)0.83%—SUN OpensolarisSamsung X14j FirmwareZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware9/2/201617/6/2026
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users…
ModificadaMedia (4.3)1.2%—Zyxel Gs1900-10hp Firmware9/2/201617/6/2026
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
ModificadaMedia (5.4)1.1%—Zyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware7/2/201617/6/2026
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
ModificadaAlta (8.8)2.2%—Samsung X14j FirmwareSUN OpensolarisZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware+17/2/201617/6/2026
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID…
ModificadaAlta (7.5)1.9%—Zyxel Gs1900-10hp Firmware7/2/201617/6/2026
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of service (device reload) via an IPv4 ICMP packet with the IP Record Route option, aka Bug ID CSCuq57512.
ModificadaAlta (8.8)0.62%—Zyxel Gs1900-10hp Firmware31/12/201517/6/2026
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaCrítica (9.8)2.8%—Zyxel Gs1900-10hp Firmware31/12/201517/6/2026
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.
ModificadaCrítica (9.8)2.7%—Zyxel Gs1900-10hp Firmware31/12/201517/6/2026
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
ModificadaAlta (8.6)1.3%—Zyxel Gs1900-10hp Firmware31/12/201517/6/2026
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
ModificadaAlta (8)1.1%—Zyxel Nbg-418n FirmwareZyxel Nbg-418n31/12/201517/6/2026
Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (8.1)3.7%—Zyxel Nbg-418n Firmware31/12/201517/6/2026
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
ModificadaAlta (8)2.2%—Zyxel Pmg5318-b20a Firmware31/12/201517/6/2026
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the user account.
ModificadaAlta (8.5)3.0%—Zyxel Pmg5318-b20a Firmware31/12/201517/6/2026
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
ModificadaCrítica (9.8)21%💥 ExploitZyxel Pmg5318-b20a Firmware31/12/201517/6/2026
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
ModificadaMedia (6.1)2.1%—Zyxel P-660hw-t1 V2 Firmware31/12/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
ModificadaCrítica (9.8)5.7%—Zyxel Nbg-418nZyxel Zynos FirmwareZyxel Pmg5318-b20a Firmware31/12/201517/6/2026
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.
ModificadaMedia (5)2.5%—Zyxel Sbg3300-n FirmwareZyxel Sbg3300-n4/10/201417/6/2026
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified "welcome message" form data that is improperly handled during use for the loginMsg variable's…
ModificadaMedia (4.3)1.2%—Zyxel Sbg3300-n FirmwareZyxel Sbg3300-n4/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "welcome message" form data that is improperly handled during rendering of the loginMessage list…
ModificadaMedia (6.8)2.6%💥 ExploitZyxel P-660hw16/6/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.
ModificadaAlta (7.9)1.1%—Zyxel N300 Netusb Nbg-419n FirmwareZyxel N300 Netusb Nbg-419n15/4/201417/6/2026
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters in input to the (1) detectWeather, (2) set_language, (3) SystemCommand, or (4) NTPSyncWithHost function in management.c, or a (5) SET COUNTRY, (6) SET WLAN SSID, (7) SET…
ModificadaAlta (7.9)0.61%—Zyxel N300 Netusb Nbg-419n FirmwareZyxel N300 Netusb Nbg-419n15/4/201417/6/2026
Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp attribute in a yweather:condition element in a forecastrss file that is processed by the checkWeather function; the (2)…
ModificadaAlta (7.8)0.75%—Zyxel N300 Netusb Nbg-419n FirmwareZyxel N300 Netusb Nbg-419n15/4/201417/6/2026
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an unspecified account, which allows remote attackers to obtain index.asp login access via an HTTP request.
Orbitaley — Vulnerabilidades