Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.27% | — | Mercury X30gAIMercury Yr1800xgAI | 28/5/2024 | 17/6/2026 | An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mercurycom A15 Firmware | 25/10/2023 | 17/6/2026 | Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Mercurycom Mac1200r Firmware | 29/5/2023 | 17/6/2026 | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | |
| Modificada | Crítica (9.3) | 1.3% | — | Mercury Sample Manager Project Mercury Sample Manager | 11/7/2022 | 17/6/2026 | The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 1.9% | — | Mercurycom Mipc451-4 Firmware | 16/6/2022 | 17/6/2026 | MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request. | |
| Modificada | Alta (7.8) | 1.5% | — | Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+2 | 10/5/2022 | 9/7/2026 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Tp-link Tl-wdr7660 FirmwareTp-link Tl-wdr7661 FirmwareTp-link Tl-wdr7620 FirmwareTp-link Tl-wdr5660 Firmware+2 | 10/5/2022 | 9/7/2026 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution. | |
| Modificada | Crítica (9.8) | 5.6% | — | Mercury Mer1200 FirmwareMercury Mer1200g Firmware | 14/10/2021 | 17/6/2026 | A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1. | |
| Modificada | Alta (7.5) | 1.6% | — | Mercusys Mercury X18g Firmware | 29/4/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed. | |
| Modificada | Media (6.1) | 1.1% | — | Mercusys Mercury X18g Firmware | 29/4/2021 | 17/6/2026 | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters. | |
| Modificada | Media (5.3) | 1.8% | — | Mercusys Mercury X18g Firmware | 7/1/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI. | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Mercusys Mercury X18g Firmware | 7/1/2021 | 17/6/2026 | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI. | |
| Modificada | Crítica (9.8) | 1.2% | — | Accenture Mercury | 27/3/2020 | 17/6/2026 | An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. | |
| Modificada | Media (6.1) | 6.6% | 💥 Exploit | Mercurycom Mr804 FirmwareMercurycom Mr804 | 19/9/2012 | 16/6/2026 | Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.2% | — | HP Mercury Testdirector FOR Quality Center | 27/5/2010 | 16/6/2026 | Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors. | |
| Modificada | Alta (9.3) | 6.8% | 💥 Exploit | Mercuryaudio Audio Player | 29/3/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file. | |
| Modificada | Alta (9.3) | 6.0% | 💥 Exploit | Mercuryaudio Audio Player | 29/3/2010 | 16/6/2026 | Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mercuryboard | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']). | |
| Modificada | Alta (7.6) | 8.7% | — | HP Mercury Quality CenterHP Testdirector | 24/2/2009 | 16/6/2026 | HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by… | |
| Modificada | Media (4.3) | 1.1% | — | Mercuryboard Message Board | 13/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained… | |
| Modificada | Media (6) | 3.6% | 💥 Exploit | David Harris Mercury 32 | 20/9/2007 | 16/6/2026 | Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211. | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | Pmail Mercury Mail Transport System | 21/8/2007 | 16/6/2026 | Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961. | |
| Modificada | Media (6.5) | 6.1% | 💥 Exploit | HP Mercury Quality Center | 6/4/2007 | 16/6/2026 | qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method. | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | HP Mercury Quality Center | 2/4/2007 | 16/6/2026 | Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property. |