Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
26.302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Anviz CX7 Firmware | 17/4/2026 | 17/6/2026 | Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual information about the deployment environment. | |
| Analizada | Media (5.3) | 0.42% | — | Anviz CX7 FirmwareAnviz CX2 Lite Firmware | 17/4/2026 | 17/6/2026 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device. | |
| Analizada | Alta (7.7) | 0.12% | — | Anviz CX7 Firmware | 17/4/2026 | 17/6/2026 | Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale. | |
| Modificada | Media (4.9) | 0.52% | — | Anviz CX7 Firmware | 17/4/2026 | 10/7/2026 | Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes. | |
| Analizada | Alta (8.8) | 0.15% | — | ZTE Nubia-in Nx809j Firmware | 17/4/2026 | 8/7/2026 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set… | |
| Pendiente de análisis | Media (5.9) | 0.11% | — | AMD Secure Processor FirmwareAIAMD ZEN 5AI | 16/4/2026 | 17/6/2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity. | |
| Analizada | Media (5.4) | 0.11% | — | Tp-link Archer C7 Firmware | 16/4/2026 | 17/6/2026 | Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 13/4/2026 | 17/6/2026 | A vulnerability was detected in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan. The manipulation of the argument wanmode/PPPOEPassword results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 13/4/2026 | 17/6/2026 | A security vulnerability has been detected in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 13/4/2026 | 17/6/2026 | A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. This affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda F451 1.0.0.7. This vulnerability affects the function fromSafeMacFilter of the file /goform/SafeMacFilter of the component httpd. Executing a manipulation of the argument page/menufacturer can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.96% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability was found in Tenda F451 1.0.0.7. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Performing a manipulation of the argument entrys results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A flaw has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function WrlclientSet of the file /goform/WrlclientSet of the component httpd. This manipulation of the argument GO causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.4) | 0.95% | — | Tenda F451 Firmware | 12/4/2026 | 17/6/2026 | A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.5) | 1.3% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex devices. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.5) | 0.41% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex EV chargers. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.5) | 0.68% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Crítica (9.8) | 1.1% | — | Sonos ERA 300 Firmware | 11/4/2026 | 17/6/2026 | Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the… | |
| Analizada | Media (5.5) | 0.78% | — | Tenda I6 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC9 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC9 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-513 Firmware | 10/4/2026 | 17/6/2026 | A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and… |