Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.7% | — | Siemens 7kg9501-0aa01-2aa1 FirmwareSiemens 7kg9501-0aa31-0aa1 FirmwareSiemens 7kg9501-0aa31-2aa1 FirmwareSiemens 7kg9501-0aa01-0aa1 Firmware | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41). The affected firmware contains a buffer overflow vulnerability in the web application that… | |
| Modificada | Alta (7.5) | 6.7% | — | StrongswanDebian LinuxFedoraproject FedoraSiemens 6gk6108-4am00-2ba2 Firmware+16 | 18/10/2021 | 17/6/2026 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dahuasecurity Ipc-hum7xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5xxx FirmwareDahuasecurity Sd1a1 Firmware+15 | 15/9/2021 | 17/6/2026 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dlink Dir-600 B1 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-645 A1 FirmwareDlink Dir-815 A1 Firmware+3 | 11/11/2019 | 17/6/2026 | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00. | |
| Modificada | Alta (7.5) | 1.6% | — | Dlink Dir-816 A1 Firmware | 11/10/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp file. This provides access to d_status.asp, version.asp, d_dhcptbl.asp, and d_acl.asp. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Dlink Dir-868l B1 FirmwareDlink Dir-817lw A1 Firmware | 11/10/2019 | 17/6/2026 | There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used… | |
| Modificada | Alta (8.8) | 1.0% | — | Broadcom Bcm4335c0 FirmwareBroadcom Bcm43438a1 FirmwareCypress Cyw20702a1kwfbg FirmwareCypress Cyw20702a1kwfbgt Firmware+59 | 7/6/2019 | 17/6/2026 | Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command. | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa | LG N1a1 Firmware | 14/5/2019 | 17/6/2026 | LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code execution. | |
| Modificada | Alta (7.5) | 1.4% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. The HTTP server could allow an attacker to overwrite the root directory of the server, resulting in a denial of service. An attacker can send an HTTP POST request to trigger… | |
| Modificada | Alta (7.5) | 1.7% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a semaphore deadlock, which prevents the device from receiving any physical or network inputs. An… | |
| Modificada | Alta (7.5) | 1.5% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_GetScreen Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted set of packets can cause an invalid memory dereference, resulting in a device reboot. | |
| Modificada | Alta (7.5) | 1.6% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_GetRawEncJpg Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an invalid memory dereference, resulting in a device reboot. | |
| Modificada | Alta (7.5) | 1.6% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the thumbnail display functionality of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a null pointer dereference, resulting in a device reboot. | |
| Modificada | Crítica (9.8) | 2.8% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. | |
| Modificada | Crítica (9.8) | 2.3% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be uploaded which will be flashed upon next reboot. An attacker can send an HTTP PUT request or upgrade firmware request… | |
| Modificada | Alta (8.8) | 0.49% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.71% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.2% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Xiaomi Mi-a1 Firmware | 24/12/2018 | 17/6/2026 | An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot. | |
| Modificada | Crítica (9.8) | 1.5% | — | D-link Dir-809 A1 FirmwareD-link Dir-809 A2 FirmwareD-link Dir-809 Guestzone Firmware | 9/10/2018 | 17/6/2026 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext. | |
| Modificada | Alta (7.5) | 1.8% | — | D-link Dir-809 A1 FirmwareD-link Dir-809 A2 FirmwareD-link Dir-809 Guestzone Firmware | 9/10/2018 | 17/6/2026 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file. | |
| Modificada | Alta (8.1) | 3.3% | — | D-link Dap-1353 H/W B1 FirmwareD-link Dap-2553 H/W A1 FirmwareD-link Dap-3520 H/W A1 Firmware | 21/4/2017 | 17/6/2026 | D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal wireless passwords and administrative usernames and passwords over SNMP. |