Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1248 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)3.7%—Totolink A3600r Firmware29/3/202617/6/2026
A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is…
AnalizadaMedia (6.3)0.25%—NEC Aterm Wg1200hp4 FirmwareNEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr Firmware+1727/3/202617/6/2026
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
AnalizadaAlta (7.1)1.2%—NEC Aterm Wx3600hp FirmwareNEC Aterm Wx1500hp Firmware27/3/202617/6/2026
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
AnalizadaMedia (6)0.50%—NEC Aterm Wx3600hp Firmware27/3/202617/6/2026
Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
AnalizadaMedia (6.3)0.23%—NEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr FirmwareNEC Aterm Wg2600hp4 Firmware+1627/3/202617/6/2026
Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network.
AnalizadaMedia (6.9)0.55%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.
AnalizadaAlta (8.6)0.67%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
AnalizadaAlta (8.7)0.51%—Buffalo Wzr-s900dhp FirmwareBuffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p Firmware+4227/3/202617/6/2026
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.
AnalizadaAlta (8.7)0.48%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.
AnalizadaAlta (8.6)1.4%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
AplazadaMedia (6.1)0.38%—Itracker360AI21/3/202617/6/2026
The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing output escaping. This…
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+392/3/202617/6/2026
Transient DOS when MAC configures config id greater than supported maximum value.
AnalizadaAlta (7.2)0.14%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+2022/3/202617/6/2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
AnalizadaAlta (7.8)0.07%—Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+1742/3/202617/6/2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1212/3/202617/6/2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
AplazadaAlta (7.4)0.16%—Cisco Nexus 3600AICisco Nexus 9500-rAI25/2/202617/6/2026
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop.
AnalizadaAlta (8.8)1.4%—Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+4824/2/202617/6/2026
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
AnalizadaMedia (4.9)1.9%—Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+4424/2/202617/6/2026
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)1.8%—Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)1.2%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)0.81%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service…
AplazadaAlta (7.2)0.40%—Ione360 ConfiguratorAI11/2/202617/6/2026
The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Parameters in all versions up to, and including, 2.0.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AnalizadaMedia (6.9)0.42%—Microcom360 Zeusweb11/2/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31.
AnalizadaMedia (5.1)0.24%—Microcom360 Zeusweb11/2/202617/6/2026
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Surname’ parameter of the ‘Create Account’ operation…