Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.51% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could… | |
| Modificada | Media (5.5) | 0.14% | — | Netis-systems Netcore Router Firmware | 7/1/2023 | 17/6/2026 | A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The… | |
| Modificada | Alta (7.5) | 0.78% | — | Netis-systems Netcore Router Firmware | 7/1/2023 | 17/6/2026 | A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.86% | — | Netis-systems Netcore Router Firmware | 7/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability. | |
| Modificada | Crítica (9.8) | 0.95% | — | Synology Router Manager | 5/1/2023 | 17/6/2026 | Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.00% | — | Synology Router Manager | 5/1/2023 | 17/6/2026 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.76% | — | Uniswap Universal Router Firmware | 4/1/2023 | 17/6/2026 | Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. | |
| Modificada | Media (5.1) | 0.72% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data. | |
| Modificada | Media (5.2) | 0.27% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords. | |
| Modificada | Alta (7.1) | 0.24% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system. | |
| Modificada | Alta (8.8) | 1.1% | — | UI Edgemax Edgerouter Firmware | 5/12/2022 | 17/6/2026 | A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mikrotik Routeros | 5/12/2022 | 17/6/2026 | Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Alta (8.8) | 1.6% | — | Mikrotik Routeros | 5/12/2022 | 17/6/2026 | Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message. | |
| Modificada | Crítica (9.8) | 0.67% | — | Inhandnetworks Inrouter302 Firmware | 9/11/2022 | 17/6/2026 | The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability. | |
| Modificada | Crítica (9.8) | 2.0% | — | Mikrotik Routeros | 15/10/2022 | 17/6/2026 | The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as… | |
| Modificada | Media (6.5) | 1.6% | — | Mikrotik Routeros | 26/8/2022 | 17/6/2026 | Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mikrotik Routeros | 25/8/2022 | 17/6/2026 | The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host. | |
| Modificada | Media (4.3) | 0.58% | — | Zoom On-premise Meeting Connector Multimedia Router | 15/6/2022 | 17/6/2026 | Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host. | |
| Modificada | Crítica (9.8) | 2.2% | — | SAP Netweaver AS AbapSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64ucSAP Router | 14/6/2022 | 17/6/2026 | Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53,… | |
| Modificada | Alta (8.1) | 1.8% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.1) | 1.5% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.0% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Media (6.5) | 2.2% | — | Mikrotik Routeros | 11/5/2022 | 17/6/2026 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modificada | Media (6.5) | 2.2% | — | Mikrotik Routeros | 11/5/2022 | 17/6/2026 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Sd-wan Vedge Router | 15/4/2022 | 17/6/2026 | A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large… |