Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 3.7% | — | Totolink A3600r Firmware | 29/3/2026 | 17/6/2026 | A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is… | |
| Analizada | Media (6.3) | 0.25% | — | NEC Aterm Wg1200hp4 FirmwareNEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr Firmware+17 | 27/3/2026 | 17/6/2026 | Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network. | |
| Analizada | Alta (7.1) | 1.2% | — | NEC Aterm Wx3600hp FirmwareNEC Aterm Wx1500hp Firmware | 27/3/2026 | 17/6/2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | |
| Analizada | Media (6) | 0.50% | — | NEC Aterm Wx3600hp Firmware | 27/3/2026 | 17/6/2026 | Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. | |
| Analizada | Media (6.3) | 0.23% | — | NEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr FirmwareNEC Aterm Wg2600hp4 Firmware+16 | 27/3/2026 | 17/6/2026 | Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network. | |
| Analizada | Media (6.9) | 0.55% | — | Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+42 | 27/3/2026 | 17/6/2026 | Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication. | |
| Analizada | Alta (8.6) | 0.67% | — | Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+42 | 27/3/2026 | 17/6/2026 | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands. | |
| Analizada | Alta (8.7) | 0.51% | — | Buffalo Wzr-s900dhp FirmwareBuffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p Firmware+42 | 27/3/2026 | 17/6/2026 | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication. | |
| Analizada | Alta (8.7) | 0.48% | — | Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+42 | 27/3/2026 | 17/6/2026 | Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products. | |
| Analizada | Alta (8.6) | 1.4% | — | Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+42 | 27/3/2026 | 17/6/2026 | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products. | |
| Aplazada | Media (6.1) | 0.38% | — | Itracker360AI | 21/3/2026 | 17/6/2026 | The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing output escaping. This… | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Aplazada | Alta (7.4) | 0.16% | — | Cisco Nexus 3600AICisco Nexus 9500-rAI | 25/2/2026 | 17/6/2026 | A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. | |
| Analizada | Alta (8.8) | 1.4% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+48 | 24/2/2026 | 17/6/2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | |
| Analizada | Media (4.9) | 1.9% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+44 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.8% | — | Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.2% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 0.81% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service… | |
| Aplazada | Alta (7.2) | 0.40% | — | Ione360 ConfiguratorAI | 11/2/2026 | 17/6/2026 | The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Parameters in all versions up to, and including, 2.0.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.9) | 0.42% | — | Microcom360 Zeusweb | 11/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31. | |
| Analizada | Media (5.1) | 0.24% | — | Microcom360 Zeusweb | 11/2/2026 | 17/6/2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Surname’ parameter of the ‘Create Account’ operation… |