Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Commscope Arris Surfboard Sbg6950ac2 Firmware26/1/202417/6/2026
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
ModificadaAlta (8.8)5.6%—Peplink Surf Soho Firmware11/10/202317/6/2026
An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability is specifically…
ModificadaAlta (8.8)5.6%—Peplink Surf Soho Firmware11/10/202317/6/2026
An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability is specifically…
ModificadaAlta (8.8)5.5%—Peplink Surf Soho Firmware11/10/202317/6/2026
An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaMedia (5.4)0.81%—Peplink Surf Soho Firmware11/10/202317/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An attacker can make an authenticated HTTP request to trigger this…
ModificadaAlta (8.8)5.9%—Peplink Surf Soho Firmware11/10/202317/6/2026
An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (8.8)5.7%—Peplink Surf Soho Firmware11/10/202317/6/2026
An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)0.86%—Nikooo777 Cksurf28/8/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in nikooo777 ckSurf up to 1.19.2. It has been declared as problematic. This vulnerability affects the function SpecListMenuDead of the file csgo/addons/sourcemod/scripting/ckSurf/misc.sp of the component Spectator List Name Handler. The manipulation of the…
ModificadaAlta (7.5)0.72%—Nosurf Project Nosurf27/12/202217/6/2026
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
ModificadaCrítica (9.8)1.1%—Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+951/12/202217/6/2026
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
ModificadaAlta (8.8)0.68%—Commscope Arris Surfboard Sbg6950ac2 FirmwareCommscope Arris Surfboard Sbg7400ac2 FirmwareCommscope Arris Surfboard Sbg7580ac FirmwareCommscope Arris Surfboard Sbg7600ac2 Firmware+115/2/202217/6/2026
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
ModificadaAlta (7.1)0.46%—Commscope Arris Surfboard Sb8200 Firmware9/11/202117/6/2026
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
ModificadaAlta (8.8)0.56%—Commscope Arris Surfboard Sb8200 Firmware21/10/202117/6/2026
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
ModificadaMedia (6.1)0.86%—Microsoft Surface PRO 3 Firmware20/10/202117/6/2026
Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
ModificadaAlta (7.5)1.3%—Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+517/10/202017/6/2026
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
ModificadaCrítica (9.8)0.73%—Eyesurfer Bflyinstallerx.ocx17/7/202017/6/2026
EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leveraged for code execution. When the vulnerable method is called, they fail to properly check the parameters that are passed…
ModificadaMedia (5.5)0.42%—Netsurf-browser NetsurfDebian Linux21/2/202016/6/2026
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
ModificadaAlta (7.5)2.0%—Netsurf-browser Libnsbmp18/2/202017/6/2026
libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.
ModificadaAlta (8.8)3.1%—Netsurf-browser Libnsgif18/2/202017/6/2026
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.
ModificadaMedia (6.5)1.3%—Netsurf-browser Libnsgif18/2/202017/6/2026
The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.
ModificadaAlta (8.8)3.1%—Netsurf-browser Libnsbmp12/2/202017/6/2026
Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.
ModificadaMedia (6.8)0.86%—Microsoft Surface HUB Firmware11/2/202017/6/2026
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.
ModificadaMedia (5.5)0.38%—Suckless SurfDebian Linux19/11/201916/6/2026
surf: cookie jar has read access from other local user
ModificadaMedia (5.5)61%—Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaAlta (7.8)1.6%—Philippine Long Distance Telephone Kasda Kw58293 FirmwarePhilippine Long Distance Telephone Speedsurf 504an Firmware21/9/201517/6/2026
Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipaddr parameter.