Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.22%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan SolutionCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vedge Cloud+315/4/202217/6/2026
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device.…
ModificadaMedia (5.4)0.57%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the web_exec parameter at /apply.cgi.
ModificadaAlta (7.5)1.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.
ModificadaCrítica (9.1)1.4%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.
ModificadaCrítica (9.8)3.6%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.8%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.8%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.
ModificadaAlta (8.1)16%—Mikrotik Routeros16/3/202217/6/2026
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.
ModificadaAlta (7.5)1.3%—Mikrotik Routeros28/2/202217/6/2026
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.
ModificadaAlta (7.5)1.2%—Mikrotik Routeros28/2/202217/6/2026
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
ModificadaMedia (6.6)98%💥 PoCApache Log4jOracle Communications Diameter Signaling RouterOracle Communications Interactive Session RecorderOracle Primavera Gateway+1828/12/202117/6/2026
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting…
ModificadaMedia (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaAlta (7)1.4%—PHPDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+125/10/202117/6/2026
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and…
ModificadaCrítica (9.8)1.7%—Juniper 128 Technology Session Smart Router Firmware19/10/202117/6/2026
The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all…
ModificadaAlta (7.5)6.6%—NettyOracle Banking ApisOracle Banking Digital ExperienceOracle Commerce Guided Search+819/10/202117/6/2026
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input…
ModificadaAlta (7.5)5.9%—NettyQuarkusOracle Banking ApisOracle Banking Digital Experience+1519/10/202117/6/2026
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
ModificadaAlta (7.5)12%—Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+1414/10/202117/6/2026
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a…
ModificadaAlta (7.3)0.43%—Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator30/9/202117/6/2026
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
ModificadaCrítica (9.8)2.0%—Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator30/9/202117/6/2026
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
Orbitaley — Vulnerabilidades