Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | 💥 PoC | Mikrotik Routeros | 7/9/2023 | 17/6/2026 | The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10… | |
| Modificada | Media (5.9) | 0.80% | — | Apollographql Apollo Router | 5/9/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be… | |
| Modificada | Alta (7.5) | 1.4% | — | O-ran-sc RIC Message Router | 1/9/2023 | 17/6/2026 | O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device. | |
| Modificada | Alta (7.5) | 0.72% | — | Synology Router Manager | 31/8/2023 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.3) | 0.79% | — | Synology Router Manager | 31/8/2023 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via unspecified vectors. | |
| Modificada | Media (6.5) | 0.78% | — | Synology Router Manager | 31/8/2023 | 17/6/2026 | Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | Synology Router Manager | 31/8/2023 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.89% | — | Nokia Service Router LinuxNokia Service Router Operating System | 29/8/2023 | 17/6/2026 | Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes. | |
| Modificada | Alta (7.5) | 2.1% | — | O-ran-sc RIC Message Router | 28/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component. | |
| Modificada | Alta (7.5) | 2.2% | — | O-ran-sc RIC Message Router | 28/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet. | |
| Modificada | Media (4.9) | 1.4% | — | Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+3 | 8/8/2023 | 17/6/2026 | In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service. | |
| Modificada | Crítica (9.6) | 1.8% | — | Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+3 | 8/8/2023 | 17/6/2026 | In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser. | |
| Modificada | Crítica (9.8) | 1.1% | — | Xiaomi Router Firmware | 2/8/2023 | 17/6/2026 | Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing. | |
| Modificada | Alta (7.2) | 1.4% | 💥 PoC | Mikrotik Routeros | 19/7/2023 | 17/6/2026 | MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system. | |
| Modificada | Alta (7.5) | 0.80% | — | UI Edgemax Edgerouter FirmwareUI Aircube Firmware | 18/7/2023 | 17/6/2026 | A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices. | |
| Modificada | Alta (7.5) | 1.0% | — | Mikrotik Routeros | 12/7/2023 | 9/7/2026 | An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. | |
| Modificada | Media (6.1) | 0.48% | — | Gira KNX IP Router Firmware | 30/6/2023 | 17/6/2026 | The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding,… | |
| Modificada | Alta (7.5) | 1.3% | — | Gira KNX IP Router Firmware | 29/6/2023 | 17/6/2026 | The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL. | |
| Modificada | Alta (7.5) | 14% | — | Wavlink Wavrouter APP | 22/6/2023 | 17/6/2026 | An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload. | |
| Modificada | Alta (7.5) | 0.88% | — | Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager | 13/6/2023 | 17/6/2026 | Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors. | |
| Modificada | Alta (8.1) | 0.97% | — | Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager | 13/6/2023 | 17/6/2026 | Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.5% | — | Synology Router Manager | 16/5/2023 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.2% | — | Synology Router Manager | 16/5/2023 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows man-in-the-middle attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 14% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer. | |
| Modificada | Media (4.9) | 3.9% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters… |