Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
309 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.41% | — | Edimax Br-6476ac Firmware | 27/1/2025 | 5/7/2026 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding. | |
| Aplazada | Alta (8.3) | 0.85% | — | Iocharger AC FirmwareAI | 9/1/2025 | 17/6/2026 | After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. The issue is addressed by requiring a… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads to command injection. The attack can be… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_nslookup leads to command injection. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command injection. The attack may be initiated… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is possible to initiate the attack remotely.… | |
| Analizada | Media (5.1) | 29% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag_traceroute leads to command injection. The attack may be… | |
| Analizada | Media (5.1) | 30% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens500-ac FirmwareEngeniustech Ens620ext Firmware | 25/11/2024 | 17/6/2026 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument https_enable leads to command injection. The attack can be… | |
| Analizada | Media (5.1) | 27% | — | Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware | 25/11/2024 | 17/6/2026 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_schedule_day_em_5 leads to command injection. It is possible to launch the attack… | |
| Modificada | Media (4.6) | 0.15% | — | Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+87 | 4/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated. | |
| Analizada | Media (6.1) | 0.68% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to bypass authentication via a specially crafted direct request when another user has an active session. | |
| Analizada | Alta (8.7) | 1.7% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to read arbitrary files and bypass authentication. | |
| Analizada | Crítica (9.4) | 0.77% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service. A specially-crafted HTTP request to pre-authentication resources… | |
| Analizada | Crítica (10) | 1.1% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to execute arbitrary code. | |
| Analizada | Crítica (9.4) | 1.3% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker to execute arbitrary OS commands via various endpoint parameters. | |
| Analizada | Alta (8.8) | 0.80% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 12/8/2024 | 17/6/2026 | Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints. | |
| Analizada | Alta (8.7) | 0.63% | — | Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+10 | 8/8/2024 | 17/6/2026 | Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication using hard-coded administrator credentials. These accounts cannot be disabled. | |
| Modificada | Alta (7.8) | 0.16% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+102 | 1/7/2024 | 17/6/2026 | Memory corruption while handling user packets during VBO bind operation. | |
| Modificada | Alta (7.8) | 0.15% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+218 | 1/7/2024 | 17/6/2026 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | |
| Modificada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+107 | 1/7/2024 | 17/6/2026 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+339 | 1/7/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+220 | 1/7/2024 | 17/6/2026 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+255 | 1/7/2024 | 17/6/2026 | Memory corruption while processing key blob passed by the user. |