Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.27%—Mercury X30gAIMercury Yr1800xgAI28/5/202417/6/2026
An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service.
ModificadaCrítica (9.8)1.8%—Mercurycom A15 Firmware25/10/202317/6/2026
Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.
ModificadaAlta (7.5)7.8%💥 ExploitMercurycom Mac1200r Firmware29/5/202317/6/2026
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
ModificadaCrítica (9.3)1.3%—Mercury Sample Manager Project Mercury Sample Manager11/7/202217/6/2026
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)1.9%—Mercurycom Mipc451-4 Firmware16/6/202217/6/2026
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
ModificadaAlta (7.8)1.5%—Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+210/5/20229/7/2026
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
ModificadaAlta (7.8)1.5%—Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+210/5/20229/7/2026
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
ModificadaCrítica (9.8)5.6%—Mercury Mer1200 FirmwareMercury Mer1200g Firmware14/10/202117/6/2026
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
ModificadaAlta (7.5)1.6%—Mercusys Mercury X18g Firmware29/4/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
ModificadaMedia (6.1)1.1%—Mercusys Mercury X18g Firmware29/4/202117/6/2026
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
ModificadaMedia (5.3)1.8%—Mercusys Mercury X18g Firmware7/1/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
ModificadaMedia (5.3)13%💥 ExploitMercusys Mercury X18g Firmware7/1/202117/6/2026
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
ModificadaCrítica (9.8)1.2%—Accenture Mercury27/3/202017/6/2026
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
ModificadaMedia (6.1)6.6%💥 ExploitMercurycom Mr804 FirmwareMercurycom Mr80419/9/201216/6/2026
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.2%—HP Mercury Testdirector FOR Quality Center27/5/201016/6/2026
Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.
ModificadaAlta (9.3)6.8%💥 ExploitMercuryaudio Audio Player29/3/201016/6/2026
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.
ModificadaAlta (9.3)6.0%💥 ExploitMercuryaudio Audio Player29/3/201016/6/2026
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.
ModificadaMedia (4)2.2%💥 ExploitDigital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+219/8/200916/6/2026
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the…
ModificadaAlta (7.5)0.97%💥 ExploitMercuryboard7/4/200916/6/2026
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
ModificadaAlta (7.6)8.7%—HP Mercury Quality CenterHP Testdirector24/2/200916/6/2026
HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by…
ModificadaMedia (4.3)1.1%—Mercuryboard Message Board13/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained…
ModificadaMedia (6)3.6%💥 ExploitDavid Harris Mercury 3220/9/200716/6/2026
Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
ModificadaAlta (7.5)65%💥 ExploitPmail Mercury Mail Transport System21/8/200716/6/2026
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
ModificadaMedia (6.5)6.1%💥 ExploitHP Mercury Quality Center6/4/200716/6/2026
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.
ModificadaAlta (9.3)40%💥 ExploitHP Mercury Quality Center2/4/200716/6/2026
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.
Orbitaley — Vulnerabilidades