Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1720 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm.
ModificadaMedia (4.9)0.79%—H3C Magic R200 Firmware21/4/202317/6/2026
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.
ModificadaMedia (5.5)0.59%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora12/4/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (6.1)0.38%—Magic-post-thumbnail Magic Post Thumbnail7/4/202317/6/2026
Unauth. Reflected Cross-site Scripting (XSS) vulnerability in Magic Post Thumbnail plugin <= 4.1.10 versions.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (4.9)0.79%—H3C Magic R100 Firmware7/4/202317/6/2026
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
ModificadaMedia (5.5)0.86%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux23/3/202317/6/2026
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When…
ModificadaMedia (6.1)0.41%—Magicform Project Magicform20/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions.
ModificadaAlta (8.8)0.25%—Metagauss Registrationmagic13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
ModificadaAlta (8.8)0.63%—Orangelab Imagemagick Engine10/2/202317/6/2026
The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action…