Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.9) | 0.67% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Media (6.1) | 0.40% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Alta (7.7) | 0.54% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Alta (7.5) | 0.55% | — | Zyxel Nwa1100-n Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by… | |
| Analizada | Media (4.4) | 0.15% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file. | |
| Analizada | Alta (8.8) | 2.7% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request. | |
| Analizada | Media (6.5) | 0.32% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication. | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 12/5/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.3) | 2.3% | — | Dlink Dcs-932l Firmware | 11/5/2026 | 17/6/2026 | D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection. | |
| Analizada | Media (5.1) | 6.1% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely. | |
| Analizada | Baja (2) | 6.0% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for… | |
| Analizada | Baja (2) | 6.1% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the file /cgi-bin/network_mgr.cgi. The manipulation leads to os command injection. The attack is possible to be carried out… | |
| Analizada | Baja (2) | 8.3% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 6.5% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the… | |
| Analizada | Baja (2) | 8.7% | — | Tenda Ac10u Firmware | 11/5/2026 | 23/7/2026 | A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dcs-935l Firmware | 11/5/2026 | 23/7/2026 | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has… | |
| Analizada | Baja (2) | 8.3% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 9/5/2026 | 24/7/2026 | A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/wl_Pass is directly passed by the attacker/so we can control the EncrypType/wl_Pass results in os command injection. The… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 9/5/2026 | 24/7/2026 | A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor… |