Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.8% | — | Tp-link Tr1200AITp-link Tr3000AITp-link Wr300AITp-link Wr1200AI+5 | 30/7/2026 | 31/8/2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a… | |
| Aplazada | Alta (7.8) | 0.15% | 💥 PoC | Unistal Systems PVT LTD Protegent 360AI | 23/7/2026 | 30/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Media (5.5) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| Aplazada | Baja (2.3) | 0.27% | — | Chef 360AI | 18/6/2026 | 22/6/2026 | A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely. | |
| Aplazada | Alta (8.6) | 0.55% | — | Chef 360AI | 18/6/2026 | 22/6/2026 | Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls… | |
| Aplazada | Alta (7.1) | 0.12% | — | Qihoo 360 Total SecurityAI | 15/6/2026 | 24/7/2026 | A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach.… | |
| Analizada | Crítica (9.8) | 1.5% | — | Microsoft Nuance Powerscribe 360Microsoft Nuance Powerscribe ONE | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Alta (8.7) | 0.57% | — | Tp-link Re305 FirmwareTp-link Re360 FirmwareTp-link Re580d FirmwareTp-link Re650 Firmware+1 | 22/5/2026 | 23/7/2026 | An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of… | |
| Pendiente de análisis | Alta (7.2) | 0.19% | — | SMA Blueplanet 100 NX3 M8AISMA Blueplanet 100 TL3 Gen2AISMA Blueplanet 105 TL3AISMA Blueplanet 105 TL3 Gen2AI+26 | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All… | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 30/9/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Alta (7.2) | 1.2% | — | Zyxel Nebula Fwa70 FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+41 | 28/4/2026 | 25/7/2026 | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Analizada | Media (6.8) | 0.85% | — | Zyxel Nr5307 FirmwareZyxel Nebula Fwa515 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 Firmware+32 | 28/4/2026 | 25/7/2026 | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device. | |
| Analizada | Alta (8.2) | 2.1% | — | Zohocorp Manageengine Log360 | 16/4/2026 | 11/8/2026 | Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Analizada | Alta (8.8) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 30/9/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Analizada | Alta (8.3) | 0.66% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal. | |
| Modificada | Alta (8.8) | 0.46% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server. | |
| Modificada | Media (6.8) | 0.88% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal. | |
| Analizada | Crítica (9.8) | 1.6% | — | Totolink A3600r Firmware | 1/4/2026 | 17/6/2026 | TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary… |