Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Huawei S9300 FirmwareHuawei S9700 FirmwareHuawei S7700 FirmwareHuawei S5300 Firmware+17 | 30/1/2018 | 17/6/2026 | Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN AC6005, AC6605, and ACU2 access controllers… | |
| Modificada | Alta (7.5) | 1.3% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+11 | 22/12/2017 | 17/6/2026 | AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR150-S… | |
| Modificada | Alta (8.8) | 2.6% | — | Tp-link Tl-wvr450l FirmwareTp-link Tl-wvr458l FirmwareTp-link Tl-wvr900l FirmwareTp-link Tl-wvr1200l Firmware+11 | 19/12/2017 | 17/6/2026 | TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd. | |
| Modificada | Alta (8.8) | 2.7% | — | Tp-link Tl-wvr450l FirmwareTp-link Tl-wvr458l FirmwareTp-link Tl-wvr900l FirmwareTp-link Tl-wvr1200l Firmware+11 | 19/12/2017 | 17/6/2026 | TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd. | |
| Modificada | Alta (8.8) | 2.4% | — | Tp-link Tl-er5510gTp-link Tl-er5520gTp-link Tl-er6120gTp-link Tl-er6520g+51 | 27/11/2017 | 17/6/2026 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd. | |
| Modificada | Media (6.5) | 1.9% | — | Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+49 | 27/11/2017 | 17/6/2026 | The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the… | |
| Modificada | Alta (8.8) | 2.9% | — | Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+49 | 27/11/2017 | 17/6/2026 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd. | |
| Modificada | Alta (8.8) | 5.6% | — | Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+49 | 27/11/2017 | 17/6/2026 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd. | |
| Modificada | Media (6.5) | 0.80% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+13 | 22/11/2017 | 17/6/2026 | AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software V200R006C10, V200R007C00, V200R007C01,… | |
| Modificada | Media (6.5) | 0.73% | — | Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+13 | 22/11/2017 | 17/6/2026 | AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software V200R006C10, V200R007C00, V200R007C01,… | |
| Modificada | Alta (7.5) | 0.97% | — | Huawei Ac6005 FirmwareHuawei Ac6605 FirmwareHuawei Ar1200 FirmwareHuawei Ar200 Firmware+19 | 22/11/2017 | 17/6/2026 | AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with… | |
| Modificada | Media (4.6) | 0.26% | — | Huawei S9300 FirmwareHuawei S9700 FirmwareHuawei S7700 FirmwareHuawei Ar200 Firmware+3 | 25/9/2017 | 17/6/2026 | Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information. | |
| Modificada | Alta (7.5) | 0.87% | — | Huawei Ar3200 FirmwareHuawei S12700 FirmwareHuawei S5300 FirmwareHuawei S5700 Firmware+5 | 2/4/2017 | 17/6/2026 | Huawei AR3200 with software V200R007C00, V200R005C32, V200R005C20; S12700 with software V200R008C00, V200R007C00; S5300 with software V200R008C00, V200R007C00, V200R006C00; S5700 with software V200R008C00, V200R007C00, V200R006C00; S6300 with software V200R008C00, V200R007C00; S6700 with software V200R008C00,… | |
| Modificada | Crítica (9.8) | 3.8% | — | Huawei Ar3200 Firmware | 24/3/2017 | 17/6/2026 | Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet. | |
| Modificada | Alta (7.5) | 1.4% | — | Huawei Ar3200 Firmware | 30/6/2016 | 17/6/2026 | Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) packets. | |
| Modificada | Media (6.5) | 1.4% | — | Huawei Ar3200 Firmware | 18/4/2016 | 17/6/2026 | Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted packets. | |
| Modificada | Alta (7.8) | 3.8% | 💥 Exploit | Huawei AR 1200Huawei AR 150Huawei AR 200Huawei AR 2200+1 | 20/6/2013 | 16/6/2026 | Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow issues. | |
| Modificada | Alta (7.6) | 3.9% | 💥 Exploit | Huawei AR 1200Huawei AR 150Huawei AR 200Huawei AR 2200+1 | 20/6/2013 | 16/6/2026 | Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Wareziz Yuhhu Superstar 2008 | 28/11/2008 | 16/6/2026 | SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter. |