Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.27% | — | Tp-link Archer Ax72 Firmware | 19/5/2026 | 24/7/2026 | In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the… | |
| Analizada | Media (5.3) | 0.18% | — | Tp-link Tl-wr720n Firmware | 17/5/2026 | 17/6/2026 | TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by… | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | AMD Power Management FirmwareAI | 15/5/2026 | 17/6/2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability. | |
| Analizada | Alta (7.3) | 0.30% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all… | |
| Analizada | Media (5) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary JavaScript code within the context of the WDU webpage. Full administrator level access to the device is possible. To… | |
| Analizada | Crítica (9.3) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this… | |
| Analizada | Alta (7.5) | 0.39% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesystem is enabled.… | |
| Analizada | Media (6.6) | 0.36% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities. | |
| Analizada | Media (6.1) | 1.4% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue… | |
| Analizada | Media (4.8) | 0.33% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are… | |
| Analizada | Alta (7.8) | 97% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-osPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 17/6/2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | |
| Analizada | Media (4.4) | 0.18% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud… | |
| Analizada | Alta (7.2) | 1.1% | 💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login… | |
| Analizada | Alta (7.2) | 0.47% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending… | |
| Analizada | Alta (7.2) | 2.6% | — | U-speed T18-21k Firmware | 13/5/2026 | 30/6/2026 | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. An authenticated user with permission to configure NTP settings can inject arbitrary system commands through crafted… | |
| Analizada | Media (6.8) | 0.33% | — | U-speed T18-21k Firmware | 13/5/2026 | 30/6/2026 | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to… | |
| Modificada | Media (6.5) | 0.46% | 💥 PoC | Openplcproject Openplc V3 Firmware | 13/5/2026 | 5/7/2026 | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file… | |
| Aplazada | Alta (7.5) | 0.33% | — | Striso-control-firmwareAI | 13/5/2026 | 17/6/2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack. | |
| Aplazada | Alta (7.5) | 0.33% | — | Striso-control-firmwareAI | 13/5/2026 | 17/6/2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons. | |
| Aplazada | Alta (7.3) | 0.24% | — | Firmament Autopilot Fmt-firmwareAI | 13/5/2026 | 17/6/2026 | Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c. | |
| Pendiente de análisis | Media (5.6) | 0.10% | — | Intel Uefi FirmwareAI | 12/5/2026 | 17/6/2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.4) | 0.09% | — | Intel Server Firmware Update Utility SoftwareAI | 12/5/2026 | 17/6/2026 | Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result… | |
| Analizada | Alta (8.2) | 0.49% | — | Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+1 | 12/5/2026 | 24/6/2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. | |
| Analizada | Alta (8.7) | 0.32% | — | Siemens Simatic CN 4100 Firmware | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavailable and cause denial-of-service conditions by overwhelming system… | |
| Analizada | Alta (8.8) | 0.30% | — | Siemens Simatic CN 4100 Firmware | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially… |