Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)4.0%—Mercury Km08-708h Giga Wifi Wave2AI14/9/202517/6/2026
A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1.1. Affected by this issue is the function sub_450B2C of the file /goform/mcr_setSysAdm. The manipulation of the argument ChgUserId leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.3)0.51%—Mercurial SCMAI17/3/202517/6/2026
A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaMedia (5.1)0.25%—Mercury Mipc552wAI11/2/202517/6/2026
Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
AplazadaMedia (6.9)0.46%—Mercury Mnvr816AI10/9/202417/6/2026
A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (4.3)0.27%—Mercury X30gAIMercury Yr1800xgAI28/5/202417/6/2026
An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service.
ModificadaCrítica (9.8)1.8%—Mercurycom A15 Firmware25/10/202317/6/2026
Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.
ModificadaAlta (7.5)7.8%💥 ExploitMercurycom Mac1200r Firmware29/5/202317/6/2026
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
ModificadaAlta (7.5)1.1%—Mercurius Project Mercurius9/1/202317/6/2026
Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions.
ModificadaMedia (5.3)0.71%—Jenkins Mercurial19/10/202217/6/2026
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
ModificadaCrítica (9.3)1.3%—Mercury Sample Manager Project Mercury Sample Manager11/7/202217/6/2026
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)1.9%—Mercurycom Mipc451-4 Firmware16/6/202217/6/2026
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
ModificadaAlta (7.5)1.5%—Jenkins Mercurial17/5/202217/6/2026
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
ModificadaAlta (7.8)1.5%—Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+210/5/20229/7/2026
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
ModificadaAlta (7.8)1.5%—Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+210/5/20229/7/2026
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
ModificadaAlta (7.5)1.6%—Mercurius Project Mercurius13/12/202117/6/2026
Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as…
ModificadaCrítica (9.8)5.6%—Mercury Mer1200 FirmwareMercury Mer1200g Firmware14/10/202117/6/2026
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
ModificadaAlta (7.5)1.6%—Mercusys Mercury X18g Firmware29/4/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
ModificadaMedia (6.1)1.1%—Mercusys Mercury X18g Firmware29/4/202117/6/2026
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
ModificadaMedia (5.3)1.8%—Mercusys Mercury X18g Firmware7/1/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
ModificadaMedia (5.3)13%💥 ExploitMercusys Mercury X18g Firmware7/1/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
ModificadaMedia (4.3)1.1%—Jenkins Mercurial4/11/202017/6/2026
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
ModificadaMedia (6.5)1.5%—Jenkins Mercurial4/11/202017/6/2026
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaCrítica (9.8)1.2%—Accenture Mercury27/3/202017/6/2026
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
ModificadaCrítica (9.8)76%💥 ExploitGit-scm GITMercurialApple XcodeEclipse Egit+212/2/202017/6/2026
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit…
ModificadaMedia (5.9)0.82%—Mercurial29/10/201916/6/2026
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.