Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.9)3.8%—Dlink Di-8100 Firmware28/4/202617/6/2026
A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware28/4/202617/6/2026
A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaAlta (8.7)0.19%—Hanwhavision Knb-2000 FirmwareHanwhavision Knb-5000n FirmwareHanwhavision Knd-2010 FirmwareHanwhavision Knd-2020rn Firmware+24928/4/202627/6/2026
Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report…
AnalizadaAlta (8.5)0.26%—Hanwhavision Knb-2000 FirmwareHanwhavision Knb-5000n FirmwareHanwhavision Knd-2010 FirmwareHanwhavision Knd-2020rn Firmware+24928/4/202627/6/2026
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's…
AnalizadaMedia (5.3)0.24%—Hanwhavision Knb-2000 FirmwareHanwhavision Knb-5000n FirmwareHanwhavision Knd-2010 FirmwareHanwhavision Knd-2020rn Firmware+24928/4/202627/6/2026
Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
AnalizadaAlta (7.2)1.2%—Zyxel Nebula Fwa70 FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+4128/4/202625/7/2026
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
AnalizadaMedia (6.8)0.85%—Zyxel Nr5307 FirmwareZyxel Nebula Fwa515 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 Firmware+3228/4/202625/7/2026
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
Pendiente de análisisAlta (7.3)1.5%—Milesight Camera FirmwareAI28/4/202625/7/2026
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
Pendiente de análisisAlta (8.6)0.29%—Milesight Aiot Camera FirmwareAI28/4/202620/7/2026
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
Pendiente de análisisAlta (7.7)0.35%—Milesight Aiot Camera FirmwareAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.4)1.0%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaCrítica (9.8)0.65%—Mercurycom Mipc252w Firmware27/4/202617/6/2026
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the same session. As a…
AnalizadaMedia (6.2)0.20%—Mercurycom Mipc252w Firmware27/4/202617/6/2026
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state,…
AnalizadaMedia (4.4)0.16%—Mercurycom Mipc252w Firmware27/4/202617/6/2026
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the same media track within a single RTSP session. This causes the server to reset the RTSP connection, leading to a…
AnalizadaAlta (7.5)0.49%—Mercurycom Mipc252w Firmware27/4/202617/6/2026
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is improperly constructed,…
ModificadaCrítica (9.8)1.5%—Tenda Ac18 Firmware27/4/202617/6/2026
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaBaja (2.1)6.5%—Tenda F456 Firmware27/4/202617/6/2026
A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.4)1.0%—Tenda F456 Firmware27/4/202617/6/2026
A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.4)1.0%—Tenda F456 Firmware27/4/202617/6/2026
A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipulation can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.
AnalizadaAlta (7.4)1.0%—Tenda F456 Firmware27/4/202617/6/2026
A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argument mit_linktype results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be…
AnalizadaAlta (7.4)1.0%—Tenda F456 Firmware27/4/202617/6/2026
A security vulnerability has been detected in Tenda F456 1.0.0.5. Impacted is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may…
AnalizadaAlta (7.4)1.0%—Tenda F456 Firmware27/4/202617/6/2026
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the…
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the…