Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

26.302 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaCrítica (9.8)2.6%—Tenda W30e Firmware21/4/202617/6/2026
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaAlta (7.3)1.6%—Tenda W30e Firmware21/4/202617/6/2026
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaAlta (8.7)0.45%—Qntmnet Qn-i-470 Firmware21/4/202617/6/2026
This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management interface. An unauthenticated attacker could exploit this vulnerability by accessing exposed API endpoints on the targeted device. Successful exploitation of this…
AnalizadaAlta (7.6)0.28%—Qntmnet Qn-i-470 Firmware21/4/202617/6/2026
This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing password guessing or brute-force attacks against user accounts, leading to unauthorized…
AnalizadaAlta (8.7)0.32%—Qntmnet Qn-i-470 Firmware21/4/202617/6/2026
This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed login attempts in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing brute force attacks against administrative credentials, leading to…
AnalizadaAlta (8.7)0.81%—Qntmnet Qn-i-470 Firmware21/4/202617/6/2026
This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary OS commands on the targeted device. Successful exploitation of this vulnerability could…
AnalizadaMedia (5.7)0.22%—Zyxel Wre6505 Firmware21/4/20268/7/2026
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator…
AnalizadaAlta (8.7)0.47%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password.
AnalizadaMedia (6.9)0.47%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration.
AnalizadaMedia (5.1)0.27%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser.
AnalizadaMedia (6.9)0.47%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.
AnalizadaMedia (6.9)0.60%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.
AnalizadaAlta (7.1)0.46%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet.
AnalizadaAlta (8.2)0.27%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack.
AnalizadaMedia (6.9)0.40%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update.
AnalizadaMedia (6.9)0.47%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication.
AnalizadaCrítica (9.3)0.71%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.
AnalizadaAlta (8.7)0.65%—Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager20/4/202617/6/2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.
AnalizadaAlta (7.5)0.48%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.
ModificadaAlta (8.8)0.54%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202610/7/2026
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
AnalizadaAlta (8.8)3.6%—Anviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level access.
AnalizadaCrítica (9.8)0.81%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
AnalizadaMedia (5.3)0.52%—Anviz CX7 Firmware17/4/202617/6/2026
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery.
AnalizadaMedia (6.5)0.31%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.