Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.11%—Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+321/6/202622/7/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
AnalizadaAlta (8)0.43%💥 PoCMediatek Mt6890 FirmwareMediatek Mt7615 FirmwareMediatek Mt7915 FirmwareMediatek Mt7916 Firmware+51/6/202622/7/2026
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.
AnalizadaMedia (5.3)0.36%—Tp-link Tl-sg108pe Firmware29/5/202622/7/2026
A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device…
AnalizadaMedia (5.9)0.19%—Macgregor Interschalt VDR G4E Firmware29/5/202622/7/2026
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
AnalizadaMedia (5.9)0.23%—Macgregor Interschalt VDR G4E Firmware29/5/202621/7/2026
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.
AnalizadaAlta (8.7)0.34%—Macgregor Interschalt VDR G4E Firmware29/5/202621/7/2026
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
AnalizadaAlta (8.7)0.34%—Macgregor Interschalt VDR G4E Firmware29/5/202621/7/2026
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
AnalizadaMedia (6.9)0.60%—Macgregor Interschalt VDR G4E Firmware29/5/202620/7/2026
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
AnalizadaBaja (2.1)0.40%—Trendnet Tew-432brp Firmware29/5/202621/7/2026
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to…
AnalizadaAlta (7.4)0.85%—Trendnet Tew-432brp Firmware29/5/202621/7/2026
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The…
AnalizadaAlta (7.4)0.83%—Trendnet Tew-432brp Firmware29/5/202621/7/2026
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been…
AnalizadaBaja (2.1)5.0%—Trendnet Tew-432brp Firmware29/5/202621/7/2026
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has…
AnalizadaBaja (2.1)5.0%—Trendnet Tew-432brp Firmware29/5/202621/7/2026
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be…
AnalizadaAlta (7.5)0.51%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.
AnalizadaAlta (7.5)0.15%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.
AnalizadaAlta (8.6)0.88%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the…
AnalizadaAlta (7.5)0.12%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaCrítica (9.3)0.41%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an…
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaAlta (8.7)0.43%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…