Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1248 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)2.8%—Tp-link Tr1200AITp-link Tr3000AITp-link Wr300AITp-link Wr1200AI+530/7/202631/8/2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a…
AplazadaAlta (7.8)0.15%💥 PoCUnistal Systems PVT LTD Protegent 360AI23/7/202630/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
AplazadaAlta (7.8)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
AplazadaAlta (7.8)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
AplazadaMedia (5.5)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
AplazadaAlta (7.5)0.43%—Panorama Viewer 360 Degree Image AND Video ViewerAI26/6/202626/6/2026
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
AplazadaBaja (2.3)0.27%—Chef 360AI18/6/202622/6/2026
A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
AplazadaAlta (8.6)0.55%—Chef 360AI18/6/202622/6/2026
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls…
AplazadaAlta (7.1)0.12%—Qihoo 360 Total SecurityAI15/6/202624/7/2026
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach.…
AnalizadaCrítica (9.8)1.5%—Microsoft Nuance Powerscribe 360Microsoft Nuance Powerscribe ONE9/6/202623/7/2026
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.2)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+2691/6/202622/7/2026
Memory corruption while processing fastboot commands with improperly formatted input.
AnalizadaAlta (7.2)0.10%—Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+2691/6/202622/7/2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
AnalizadaMedia (6.4)0.06%—Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+2321/6/202622/7/2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
AnalizadaAlta (8.7)0.57%—Tp-link Re305 FirmwareTp-link Re360 FirmwareTp-link Re580d FirmwareTp-link Re650 Firmware+122/5/202623/7/2026
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of…
Pendiente de análisisAlta (7.2)0.19%—SMA Blueplanet 100 NX3 M8AISMA Blueplanet 100 TL3 Gen2AISMA Blueplanet 105 TL3AISMA Blueplanet 105 TL3 Gen2AI+2612/5/202617/6/2026
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All…
AnalizadaAlta (7.8)0.07%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/202630/9/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AnalizadaAlta (7.2)1.2%—Zyxel Nebula Fwa70 FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+4128/4/202625/7/2026
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
AnalizadaMedia (6.8)0.85%—Zyxel Nr5307 FirmwareZyxel Nebula Fwa515 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 Firmware+3228/4/202625/7/2026
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
AnalizadaAlta (8.2)2.1%—Zohocorp Manageengine Log36016/4/202611/8/2026
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
Pendiente de análisisAlta (8.1)2.6%—Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI16/4/202617/6/2026
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
AnalizadaAlta (8.8)0.17%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/202630/9/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
AnalizadaAlta (8.3)0.66%—Kovai Biztalk3603/4/202624/7/2026
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.
ModificadaAlta (8.8)0.46%—Kovai Biztalk3603/4/202624/7/2026
An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
ModificadaMedia (6.8)0.88%—Kovai Biztalk3603/4/202624/7/2026
An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.
AnalizadaCrítica (9.8)1.6%—Totolink A3600r Firmware1/4/202617/6/2026
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary…