Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

2279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.68%—Tenda Ch22 Firmware25/12/20257/10/2026
Se ha identificado una debilidad en Tenda CH22 1.0.0.1. Afecta a una función desconocida del archivo /public/. La ejecución de manipulación puede conducir a un salto de ruta. El ataque puede lanzarse de forma remota. El exploit se ha puesto a disposición del público y podría ser explotado.
ModificadaMedia (5.5)12%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed…
ModificadaAlta (8.9)1.2%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request Handler. This manipulation of the argument page causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaAlta (8.9)1.0%—Tenda Wh450 Firmware22/12/202517/6/2026
A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.5)0.55%—Tenda Wh450 Firmware22/12/202517/6/2026
A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
AnalizadaAlta (8.9)1.0%—Tenda Wh450 Firmware22/12/202517/6/2026
A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.9)0.97%—Tenda Wh450 Firmware22/12/202517/6/2026
A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has…
AnalizadaAlta (7.4)0.75%—Tenda Fh1201 FirmwareTenda Fh1206 Firmware21/12/202517/6/2026
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack is possible to be carried out remotely. The…
AnalizadaAlta (7.4)0.74%—Tenda Fh1201 Firmware21/12/202528/9/2026
Una vulnerabilidad ha sido encontrada en Tenda FH1201 1.2.0.14(408). Afectada es la función sprintf del archivo /goform/SetIpBind. Tal manipulación del argumento page conduce a un desbordamiento de búfer basado en pila. El ataque puede ser realizado desde remoto. El exploit ha sido divulgado al público y puede ser…
AnalizadaAlta (7.4)0.78%—Tenda Ac18 Firmware21/12/202528/9/2026
Una vulnerabilidad fue detectada en Tenda AC18 15.03.05.05. Esto afecta a la función sprintf del archivo /goform/SetDlnaCfg del componente HTTP Request Handler. La manipulación del argumento scanList resulta en desbordamiento de búfer basado en pila. El ataque puede ser ejecutado remotamente. El exploit es ahora…
AnalizadaAlta (7.4)0.74%—Tenda Ac18 Firmware21/12/202517/6/2026
A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The…
ModificadaAlta (8.9)6.7%—Tenda Wh450 Firmware18/12/202517/6/2026
A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made…
ModificadaAlta (8.9)0.98%—Tenda Wh450 Firmware18/12/202517/6/2026
A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTTP Request Handler. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to…
AnalizadaMedia (6.5)0.38%—Tenda Ac10 Firmware17/12/202517/6/2026
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.
AnalizadaCrítica (9.8)0.69%—Tenda Ac10 Firmware17/12/202517/6/2026
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
ModificadaAlta (8.9)0.98%—Tenda Wh450 Firmware14/12/202528/9/2026
Una falla de seguridad ha sido descubierta en Tenda WH450 1.0.0.18. Afectada es una función desconocida del archivo /goform/DhcpListClient del componente HTTP Request Handler. La manipulación del argumento page resulta en desbordamiento de búfer basado en pila. El ataque puede ser ejecutado remotamente. El exploit ha…
ModificadaAlta (7.4)0.74%—Tenda Ac20 Firmware14/12/20257/10/2026
Se ha identificado una debilidad en Tenda AC20 16.03.08.12. Esto afecta la función httpd del archivo /goform/openSchedWifi. La ejecución de una manipulación del argumento schedStartTime/schedEndTime puede llevar a un desbordamiento de búfer. El ataque puede realizarse de forma remota. El exploit se ha puesto a…
ModificadaAlta (7.4)3.3%—Tenda Ac20 Firmware14/12/20257/10/2026
Una falla de seguridad ha sido descubierta en Tenda AC20 16.03.08.12. El elemento afectado es la función formSetRebootTimer del archivo /goform/SetSysAutoRebbotCfg del componente httpd. Realizar una manipulación del argumento rebootTime resulta en un desbordamiento de búfer basado en pila. El ataque es posible de…
AnalizadaAlta (7.4)3.3%—Tenda Ac20 Firmware14/12/20257/10/2026
Una vulnerabilidad fue identificada en Tenda AC20 16.03.08.12. El elemento afectado es la función formSetPPTPUserList del archivo /goform/setPptpUserList del componente httpd. Dicha manipulación del argumento list conduce a un desbordamiento de búfer basado en pila. El ataque puede ser ejecutado remotamente. El…
AnalizadaMedia (5.5)0.44%—Fabian Simple Attendance Record System14/12/20257/10/2026
Una vulnerabilidad fue encontrada en code-projects Simple Attendance Record System 2.0. El elemento afectado es una función desconocida del archivo /check.php. Realizar la manipulación del argumento student resulta en inyección SQL. La explotación remota del ataque es posible. El exploit ha sido hecho público y podría…
ModificadaBaja (2.9)0.29%—Tenda AX9 Firmware13/12/20257/10/2026
Una falla de seguridad ha sido descubierta en Tenda AX9 22.03.01.46. Esto afecta la función image_check del componente httpd. La manipulación resulta en el uso de un hash débil. Es posible lanzar el ataque remotamente. Un alto nivel de complejidad está asociado con este ataque. Se indica que la explotabilidad es…
ModificadaAlta (7.4)0.76%—Tenda Ch22 Firmware11/12/20257/10/2026
Se ha descubierto un fallo de seguridad en Tenda CH22 1.0.0.1. Esto afecta a la función frmL7ImForm del archivo /goform/L7Im. Realizar una manipulación del argumento page provoca un desbordamiento de búfer. La explotación remota del ataque es posible. El exploit ha sido liberado al público y puede ser utilizado para…