Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.93% | — | Tenda AC8 Firmware | 24/8/2023 | 17/6/2026 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC8 Firmware | 24/8/2023 | 17/6/2026 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda AC8 Firmware | 24/8/2023 | 17/6/2026 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC8 Firmware | 24/8/2023 | 17/6/2026 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC8 Firmware | 24/8/2023 | 17/6/2026 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg. | |
| Modificada | Alta (7.5) | 0.81% | — | Tenda AC8 Firmware | 21/8/2023 | 9/7/2026 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function. | |
| Modificada | Alta (7.5) | 0.81% | — | Tenda AC8 Firmware | 21/8/2023 | 9/7/2026 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function. | |
| Modificada | Alta (7.5) | 0.81% | — | Tenda AC8 Firmware | 21/8/2023 | 9/7/2026 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC8 FirmwareTenda AC6 Firmware+3 | 7/8/2023 | 17/6/2026 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function. | |
| Modificada | Crítica (9.8) | 0.85% | — | Tenda Ac1206 FirmwareTenda AC5 FirmwareTenda AC9 FirmwareTenda AC8 Firmware+1 | 7/8/2023 | 17/6/2026 | Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC8 FirmwareTenda AC6 Firmware+4 | 7/8/2023 | 17/6/2026 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function. | |
| Modificada | Crítica (9.8) | 1.2% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function. | |
| Modificada | Alta (7.5) | 0.92% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. | |
| Modificada | Crítica (9.8) | 0.86% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 PoC | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function. | |
| Modificada | Media (4.9) | 0.49% | — | Dell Idrac8 Firmware | 18/1/2023 | 17/6/2026 | Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. | |
| Modificada | Alta (7.2) | 28% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system. | |
| Modificada | Media (4.3) | 0.69% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate. | |
| Modificada | Media (6.1) | 1.0% | — | Dell Idrac8 Firmware | 8/3/2021 | 17/6/2026 | Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections. | |
| Modificada | Crítica (9.8) | 3.8% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 31/3/2020 | 17/6/2026 | Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data. | |
| Modificada | Media (4.3) | 0.88% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 7/11/2019 | 17/6/2026 | Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as… | |
| Modificada | Crítica (9.8) | 4.2% | — | Dell Idrac6 FirmwareDell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or… | |
| Modificada | Media (6.8) | 0.42% | — | Dell Idrac7 FirmwareDell Idrac8 Firmware | 13/12/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell. |