Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)6.7%—Aztech Dsl5005enAI24/9/202517/6/2026
Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.
AplazadaMedia (5.7)0.27%—ZTE T5400AI16/9/202517/6/2026
There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface.
AplazadaBaja (3.5)0.24%—ZTE T5400AI16/9/202517/6/2026
There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers can obtain information through interfaces without authorization, causing the risk of information disclosure.
AplazadaMedia (5.7)0.27%—ZTE F50AI15/8/202517/6/2026
There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface
AplazadaAlta (8.7)1.4%—ZTE Zxhn-f660tAIZTE Zxhn-f660aAI31/7/202517/6/2026
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.
AnalizadaAlta (7.5)0.40%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL.
AnalizadaAlta (7.8)0.32%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
AnalizadaAlta (7.5)0.36%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
AnalizadaAlta (7.5)0.36%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.
AnalizadaMedia (6.5)0.29%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
AnalizadaAlta (7.5)0.38%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
AnalizadaMedia (5.3)0.24%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
AnalizadaMedia (5.3)0.24%—ZTE Goldendb11/3/202517/6/2026
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.
AnalizadaAlta (7.5)0.31%—ZTE Goldendb11/3/202517/6/2026
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.
AnalizadaMedia (4.3)0.24%—ZTE Goldendb11/3/202517/6/2026
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.
AnalizadaMedia (4.3)0.25%—ZTE Goldendb11/3/202517/6/2026
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.
AnalizadaAlta (7.5)0.39%—ZTE Goldendb11/3/202517/6/2026
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.
AplazadaMedia (5.3)0.29%—ZTE GoldendbAI11/3/202517/6/2026
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.
AplazadaMedia (4.2)0.13%—ZtelineAI7/3/202517/6/2026
There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.
AplazadaMedia (5.9)0.29%—Aazztech WP CookieAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aazztech WP Cookie wp-cookie allows Stored XSS.This issue affects WP Cookie: from n/a through <= 1.0.0.
AnalizadaCrítica (9)0.83%—ZTE Zenic ONE R5830/12/202417/6/2026
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.
ModificadaAlta (8.8)0.69%—ZTE Nh8091 Firmware18/11/202417/6/2026
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
AnalizadaMedia (6.5)0.30%—ZTE Zxr10 1800-2s FirmwareZTE Zxr10 2800-4 FirmwareZTE Zxr10 3800-8 FirmwareZTE Zxr10 160 Firmware29/10/202417/6/2026
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
AnalizadaAlta (8.8)1.2%—ZTE Mf258k PRO Firmware29/10/202417/6/2026
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
AnalizadaCrítica (9.8)0.95%—ZTE Wrtm326 Firmware18/10/202417/6/2026
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.