Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 4.0% | — | Mercury Km08-708h Giga Wifi Wave2AI | 14/9/2025 | 17/6/2026 | A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1.1. Affected by this issue is the function sub_450B2C of the file /goform/mcr_setSysAdm. The manipulation of the argument ChgUserId leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.3) | 0.51% | — | Mercurial SCMAI | 17/3/2025 | 17/6/2026 | A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.1) | 0.25% | — | Mercury Mipc552wAI | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Aplazada | Media (6.9) | 0.46% | — | Mercury Mnvr816AI | 10/9/2024 | 17/6/2026 | A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (4.3) | 0.27% | — | Mercury X30gAIMercury Yr1800xgAI | 28/5/2024 | 17/6/2026 | An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mercurycom A15 Firmware | 25/10/2023 | 17/6/2026 | Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Mercurycom Mac1200r Firmware | 29/5/2023 | 17/6/2026 | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | |
| Modificada | Alta (7.5) | 1.1% | — | Mercurius Project Mercurius | 9/1/2023 | 17/6/2026 | Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions. | |
| Modificada | Media (5.3) | 0.71% | — | Jenkins Mercurial | 19/10/2022 | 17/6/2026 | Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access. | |
| Modificada | Crítica (9.3) | 1.3% | — | Mercury Sample Manager Project Mercury Sample Manager | 11/7/2022 | 17/6/2026 | The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 1.9% | — | Mercurycom Mipc451-4 Firmware | 16/6/2022 | 17/6/2026 | MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.5% | — | Jenkins Mercurial | 17/5/2022 | 17/6/2026 | Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents. | |
| Modificada | Alta (7.8) | 1.5% | — | Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+2 | 10/5/2022 | 9/7/2026 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+2 | 10/5/2022 | 9/7/2026 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution. | |
| Modificada | Alta (7.5) | 1.6% | — | Mercurius Project Mercurius | 13/12/2021 | 17/6/2026 | Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as… | |
| Modificada | Crítica (9.8) | 5.6% | — | Mercury Mer1200 FirmwareMercury Mer1200g Firmware | 14/10/2021 | 17/6/2026 | A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1. | |
| Modificada | Alta (7.5) | 1.6% | — | Mercusys Mercury X18g Firmware | 29/4/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed. | |
| Modificada | Media (6.1) | 1.1% | — | Mercusys Mercury X18g Firmware | 29/4/2021 | 17/6/2026 | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters. | |
| Modificada | Media (5.3) | 1.8% | — | Mercusys Mercury X18g Firmware | 7/1/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI. | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Mercusys Mercury X18g Firmware | 7/1/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI. | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Mercurial | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Mercurial | 4/11/2020 | 17/6/2026 | Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Crítica (9.8) | 1.2% | — | Accenture Mercury | 27/3/2020 | 17/6/2026 | An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. | |
| Modificada | Crítica (9.8) | 76% | 💥 Exploit | Git-scm GITMercurialApple XcodeEclipse Egit+2 | 12/2/2020 | 17/6/2026 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit… | |
| Modificada | Media (5.9) | 0.82% | — | Mercurial | 29/10/2019 | 16/6/2026 | Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack. |