Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.50% | — | Gofiber Fiber | 22/5/2025 | 17/6/2026 | Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since… | |
| Analizada | Media (5.1) | 7.7% | — | Fiberhome An5506-01a Firmware | 24/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The attack may be launched remotely. The… | |
| Analizada | Media (4.8) | 0.61% | — | Fiberhome An5506-01-a Firmware | 24/2/2025 | 17/6/2026 | A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be launched remotely. The vendor was contacted… | |
| Analizada | Media (4.8) | 0.78% | — | Fiberhome An5506-01-a Firmware | 24/2/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argument pf_Description leads to cross site scripting. It is possible to launch the… | |
| Analizada | Media (4.8) | 0.78% | — | Fiberhome An5506-01-a Firmware | 24/2/2025 | 17/6/2026 | A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of the argument url_IP leads to cross site scripting. The attack may be initiated… | |
| Aplazada | Baja (2.3) | 0.29% | — | Bharti Airtel Xstream FiberAI | 6/2/2025 | 17/6/2026 | A vulnerability was found in Bharti Airtel Xstream Fiber up to 20250123. It has been rated as problematic. This issue affects some unknown processing of the component WiFi Password Handler. The manipulation leads to use of weak credentials. The attack needs to be done within the local network. The complexity of an… | |
| Aplazada | Media (4.8) | 0.27% | — | Fiberhome Hg6544cAI | 1/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized | |
| Analizada | Crítica (9.8) | 0.69% | — | Gofiber Fiber | 1/7/2024 | 17/6/2026 | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a session with that key. If a website relies on… | |
| Aplazada | Media (6.9) | 0.43% | — | Genexis Tilgin Fiber Home Gateway Hg1522AI | 26/6/2024 | 17/6/2026 | A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be… | |
| Analizada | Crítica (9.8) | 0.66% | — | Gofiber Fiber | 21/2/2024 | 17/6/2026 | Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard (`*`) while also having… | |
| Modificada | Media (6.1) | 0.48% | — | Gofiber Django | 11/1/2024 | 17/6/2026 | This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users'… | |
| Modificada | Alta (8.8) | 0.27% | — | Gofiber Fiber | 16/10/2023 | 17/6/2026 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf,… | |
| Modificada | Alta (8.8) | 0.31% | — | Gofiber Fiber | 16/10/2023 | 17/6/2026 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf of a user. This vulnerability can allow an attacker to inject arbitrary values… | |
| Modificada | Media (5.3) | 0.66% | — | Gofiber Fiber | 8/9/2023 | 17/6/2026 | Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properly restrict access to localhost. This issue impacts users of our project who rely on the `ctx.IsFromLocal` method to restrict access to localhost requests. If exploited, it could allow unauthorized… | |
| Modificada | Alta (7.2) | 5.2% | — | Eparks Fiberlink 210 Firmware | 23/5/2023 | 17/6/2026 | An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter. | |
| Modificada | Alta (8.8) | 35% | — | Intelbras Wifiber 120ac Inmesh Firmware | 25/12/2022 | 17/6/2026 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute. | |
| Modificada | Media (5.3) | 0.44% | — | UI Airfiber Gigabeam FirmwareUI Airfiber 60-xg FirmwareUI Airfiber 60-hd FirmwareUI Airfiber 60-lr Firmware+2 | 23/12/2022 | 17/6/2026 | An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device. | |
| Modificada | Media (5.4) | 3.1% | — | Fiberhome An5506-02-b Firmware | 15/9/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field. | |
| Modificada | Alta (7.5) | 2.4% | — | Fiberhome Hg150-ub Firmware | 29/8/2022 | 17/6/2026 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed. | |
| Modificada | Media (5.4) | 2.5% | — | Fiberhome Hg150-ub Firmware | 18/5/2022 | 17/6/2026 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS. | |
| Modificada | Alta (8.8) | 10% | — | Fiberhome An5506-01-a FirmwareFiberhome An5506-01-b FirmwareFiberhome An5506-02-b FirmwareFiberhome An5506-04-b Firmware+2 | 16/12/2021 | 9/7/2026 | FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon. | |
| Modificada | Alta (7.5) | 14% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string. | |
| Modificada | Alta (7.5) | 18% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram. | |
| Modificada | Crítica (9.8) | 20% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server. | |
| Modificada | Alta (7.5) | 19% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions. |