Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.38% | — | Dlink Wireless RouterAI | 17/6/2024 | 17/6/2026 | Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL. | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Asus RouterAI | 14/6/2024 | 17/6/2026 | Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device. | |
| Aplazada | Crítica (9.8) | 43% | 💥 Exploit | Asus RouterAI | 14/6/2024 | 17/6/2026 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | |
| Aplazada | Alta (7.2) | 0.83% | — | Asus RouterAI | 14/6/2024 | 17/6/2026 | Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device. | |
| Aplazada | Alta (8.7) | 1.3% | — | Contemporary Control Systems Basrouter BacnetAI | 14/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.5) | 0.61% | — | Mikrotik Routeros | 3/5/2024 | 17/6/2026 | Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Router… | |
| Aplazada | Crítica (9) | 0.73% | — | Apollo RouterAI | 2/5/2024 | 17/6/2026 | Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug that in limited circumstances, could lead to unexpected operations being executed which can result in unintended data or effects. This only… | |
| Aplazada | Media (6.5) | 0.44% | — | Contemporary Controls Basrouter Bacnet Basrt-bAI | 27/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of… | |
| Aplazada | Alta (8.8) | 2.0% | 💥 PoC | Asus Wifi RouterAI | 15/4/2024 | 17/6/2026 | Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request. | |
| Analizada | Alta (7.7) | 0.24% | — | Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware | 5/4/2024 | 17/6/2026 | Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application | |
| Aplazada | Media (6.8) | 0.33% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AI | 5/4/2024 | 17/6/2026 | SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page. | |
| Aplazada | Alta (8.8) | 0.54% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AISpacex Starlink DishAI | 5/4/2024 | 17/6/2026 | SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack. | |
| Aplazada | Media (4.3) | 0.25% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request. | |
| Aplazada | Alta (7.1) | 0.69% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. | |
| Analizada | Alta (7.5) | 0.77% | — | Apollographql Apollo Router | 21/3/2024 | 17/6/2026 | The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes`… | |
| Aplazada | Media (6.5) | 0.21% | — | Movistar 4G RouterAIMovistar ES Wld71-t1AI | 13/3/2024 | 17/6/2026 | Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application in which they are currently authenticated. | |
| Aplazada | Alta (7.8) | 0.74% | — | Movistar 4G RouterAI | 13/3/2024 | 17/6/2026 | Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'. | |
| Aplazada | Alta (8.8) | 0.28% | — | Movistar 4G Router E S Wld71-t1 V2.0.201820AI | 13/3/2024 | 17/6/2026 | The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides access to a shell with root privileges. | |
| Modificada | Media (5.3) | 0.47% | — | Mikrotik Routeros | 14/11/2023 | 17/6/2026 | MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API. | |
| Modificada | Media (6.6) | 0.96% | — | Netmodule Router Software | 22/10/2023 | 17/6/2026 | The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap… | |
| Modificada | Alta (7.5) | 0.73% | — | Apollographql Apollo RouterApollographql Apollo Helms-charts Router | 18/10/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send… | |
| Modificada | Alta (8.1) | 1.1% | — | Xiaomi Router Ax3200 Firmware | 11/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | |
| Modificada | Alta (7.2) | 0.97% | — | Xiaomi Router Ax3200 Firmware | 11/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | |
| Modificada | Alta (7.2) | 0.58% | — | Xiaomi Router Ax3200 Firmware | 11/10/2023 | 17/6/2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers. | |
| Modificada | Media (4.3) | 0.28% | — | Mitel Connect Mobility Router | 14/9/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL,… |