Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.51%—Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware12/1/202317/6/2026
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could…
ModificadaMedia (5.5)0.14%—Netis-systems Netcore Router Firmware7/1/202317/6/2026
A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The…
ModificadaAlta (7.5)0.78%—Netis-systems Netcore Router Firmware7/1/202317/6/2026
A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The…
ModificadaCrítica (9.8)0.86%—Netis-systems Netcore Router Firmware7/1/202317/6/2026
A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.
ModificadaCrítica (9.8)0.95%—Synology Router Manager5/1/202317/6/2026
Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via unspecified vectors.
ModificadaAlta (7.5)1.00%—Synology Router Manager5/1/202317/6/2026
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (7.5)0.76%—Uniswap Universal Router Firmware4/1/202317/6/2026
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
ModificadaMedia (5.1)0.72%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
ModificadaMedia (5.2)0.27%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
ModificadaAlta (7.1)0.24%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
ModificadaAlta (8.8)1.1%—UI Edgemax Edgerouter Firmware5/12/202217/6/2026
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
ModificadaCrítica (9.8)1.4%—Mikrotik Routeros5/12/202217/6/2026
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.
ModificadaAlta (8.8)1.6%—Mikrotik Routeros5/12/202217/6/2026
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
ModificadaCrítica (9.8)0.67%—Inhandnetworks Inrouter302 Firmware9/11/202217/6/2026
The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.
ModificadaCrítica (9.8)2.0%—Mikrotik Routeros15/10/202217/6/2026
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as…
ModificadaMedia (6.5)1.6%—Mikrotik Routeros26/8/202217/6/2026
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
ModificadaCrítica (9.8)1.5%—Mikrotik Routeros25/8/202217/6/2026
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.
ModificadaMedia (4.3)0.58%—Zoom On-premise Meeting Connector Multimedia Router15/6/202217/6/2026
Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host.
ModificadaCrítica (9.8)2.2%—SAP Netweaver AS AbapSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64ucSAP Router14/6/202217/6/2026
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53,…
ModificadaAlta (8.1)1.8%—Inhandnetworks Inrouter302 Firmware12/5/202217/6/2026
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
ModificadaMedia (6.1)1.5%—Inhandnetworks Inrouter302 Firmware12/5/202217/6/2026
A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (8.8)2.0%—Inhandnetworks Inrouter302 Firmware12/5/202217/6/2026
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaMedia (6.5)2.2%—Mikrotik Routeros11/5/202217/6/2026
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModificadaMedia (6.5)2.2%—Mikrotik Routeros11/5/202217/6/2026
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModificadaMedia (5.5)0.20%—Cisco Sd-wan Vedge Router15/4/202217/6/2026
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large…
Orbitaley — Vulnerabilidades