Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)8.5%—Wavlink Wl-nu516u1 Firmware9/5/202624/7/2026
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the…
AnalizadaBaja (2.1)8.5%—Wavlink Wl-nu516u1 Firmware9/5/202624/7/2026
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaBaja (2.1)8.5%—Wavlink Wl-nu516u1 Firmware9/5/202624/7/2026
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AnalizadaAlta (7.4)0.99%—Tenda Cx12l Firmware8/5/202617/6/2026
A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaCrítica (9.8)0.71%—Yarbo Lawn Mower FirmwareYarbo Lawn Mower PRO Firmware7/5/202617/6/2026
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind.
AnalizadaCrítica (9.8)0.67%—Yarbo Lawn Mower FirmwareYarbo Lawn Mower PRO Firmware7/5/202617/6/2026
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them.
AnalizadaCrítica (9.8)0.70%—Yarbo Lawn Mower FirmwareYarbo Lawn Mower PRO Firmware7/5/202617/6/2026
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.
AnalizadaMedia (5.3)0.30%—Hitachi VSP E1090h FirmwareHitachi VSP E790h FirmwareHitachi VSP E590h FirmwareHitachi VSP E390h Firmware+167/5/202617/6/2026
Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block…
AnalizadaCrítica (9.8)0.55%—Hitachi Virtual Storage ONE BlockHitachi VSP G130 FirmwareHitachi VSP G150 FirmwareHitachi VSP G350 Firmware+167/5/202617/6/2026
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One…
AnalizadaAlta (8)0.34%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+337/5/202617/6/2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
AnalizadaMedia (6.8)0.25%💥 PoCZTE Zx297520v3 Firmware7/5/202617/6/2026
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure…
AnalizadaCrítica (9.3)32%⚠ Explotación activa💥 PoCPaloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware6/5/202617/6/2026
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this…
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
AnalizadaAlta (7.4)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be…
AnalizadaAlta (8.9)1.9%—Dlink Di-8100 Firmware5/5/202624/7/2026
A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (8.9)1.9%—Dlink Di-8100 Firmware5/5/202624/7/2026
A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the…
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202620/7/2026
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
AnalizadaCrítica (9.8)0.85%—Dlink Dir-456u Firmware4/5/202617/6/2026
D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks" and the static password "whdrv01_dlob_dir456U" read from /etc/config/image_sign. The custom telnetd binary accepts a…
AnalizadaAlta (8.8)0.98%—Dlink Dir-600l Firmware4/5/202617/6/2026
D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaAlta (8.8)0.98%—Dlink Dir-600l Firmware4/5/202617/6/2026
D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaAlta (8.8)0.98%—Dlink Dir-605l Firmware4/5/202617/6/2026
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaAlta (8.8)0.47%—Dlink Dir-605l Firmware4/5/202617/6/2026
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaCrítica (9.8)0.18%—Qualcomm Qca7005 Firmware4/5/202617/6/2026
Buffer overflow due to incorrect authorization in PLC FW
AnalizadaAlta (7.8)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+204/5/202617/6/2026
Memory corruption while processing IOCTL command when device is in power-save state.