Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+32 | 1/6/2026 | 22/7/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | |
| Analizada | Alta (8) | 0.43% | 💥 PoC | Mediatek Mt6890 FirmwareMediatek Mt7615 FirmwareMediatek Mt7915 FirmwareMediatek Mt7916 Firmware+5 | 1/6/2026 | 22/7/2026 | In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295. | |
| Analizada | Media (5.3) | 0.36% | — | Tp-link Tl-sg108pe Firmware | 29/5/2026 | 22/7/2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device… | |
| Analizada | Media (5.9) | 0.19% | — | Macgregor Interschalt VDR G4E Firmware | 29/5/2026 | 22/7/2026 | Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. | |
| Analizada | Media (5.9) | 0.23% | — | Macgregor Interschalt VDR G4E Firmware | 29/5/2026 | 21/7/2026 | An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. | |
| Analizada | Alta (8.7) | 0.34% | — | Macgregor Interschalt VDR G4E Firmware | 29/5/2026 | 21/7/2026 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. | |
| Analizada | Alta (8.7) | 0.34% | — | Macgregor Interschalt VDR G4E Firmware | 29/5/2026 | 21/7/2026 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. | |
| Analizada | Media (6.9) | 0.60% | — | Macgregor Interschalt VDR G4E Firmware | 29/5/2026 | 20/7/2026 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. | |
| Analizada | Baja (2.1) | 0.40% | — | Trendnet Tew-432brp Firmware | 29/5/2026 | 21/7/2026 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to… | |
| Analizada | Alta (7.4) | 0.85% | — | Trendnet Tew-432brp Firmware | 29/5/2026 | 21/7/2026 | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The… | |
| Analizada | Alta (7.4) | 0.83% | — | Trendnet Tew-432brp Firmware | 29/5/2026 | 21/7/2026 | A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 5.0% | — | Trendnet Tew-432brp Firmware | 29/5/2026 | 21/7/2026 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has… | |
| Analizada | Baja (2.1) | 5.0% | — | Trendnet Tew-432brp Firmware | 29/5/2026 | 21/7/2026 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (7.5) | 0.51% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured. | |
| Analizada | Alta (7.5) | 0.15% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled. | |
| Analizada | Alta (8.6) | 0.88% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Alta (7.5) | 0.12% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host. | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 0.41% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Alta (8.7) | 0.43% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device. | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… |