Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.50% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑middle (MITM) attack. This could enable unauthorized access if captured credentials are reused.This issue affects Archer AX53 v1.0: through… | |
| Modificada | Alta (7.3) | 0.51% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a field whose length exceeds the maximum expected value.This issue… | |
| Modificada | Alta (7.3) | 0.51% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet whose length exceeds the maximum expected value.This issue affects Archer AX53… | |
| Modificada | Alta (7.3) | 0.51% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing an excessive number of fields with zero‑length values.This issue affects… | |
| Modificada | Alta (7.3) | 0.45% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing an excessive number of fields with zero‑length values.This issue affects… | |
| Modificada | Alta (7.3) | 0.45% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The vulnerability arises from improper validation of a packet field whose offset is used to determine the write location… | |
| Modificada | Alta (7.3) | 0.45% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a field whose length exceeds the maximum expected value.This issue… | |
| Modificada | Alta (7.3) | 0.45% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet whose length exceeds the maximum expected value.This issue affects Archer AX53… | |
| Modificada | Alta (7.3) | 0.45% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted set of network packets containing an excessive number of host entries This issue affects Archer… | |
| Analizada | Media (6.8) | 0.38% | — | Tp-link Archer Be230 Firmware | 3/2/2026 | 17/6/2026 | An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by restoring a crafted configuration file containing an excessively long parameter. Restoring such a file can cause the device to become unresponsive, requiring a reboot to restore normal operation. This… | |
| Analizada | Media (6.8) | 0.24% | — | Tp-link Archer Be230 Firmware | 3/2/2026 | 17/6/2026 | A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a crafted request to cause the device’s web service to become unresponsive, resulting in a denial of service condition. A network adjacent attacker with high privileges could cause the device’s web… | |
| Modificada | Alta (8.6) | 0.55% | — | Tp-link Archer Ax53 Firmware | 3/2/2026 | 22/9/2026 | Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field. This issue affects Archer AX53 v1.0: through 1.3.1… | |
| Modificada | Alta (8.6) | 2.1% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe… | |
| Analizada | Alta (8.5) | 2.7% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 2.5% | 💥 PoC | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 2.8% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2 and Archer AXE75 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Analizada | Alta (8.5) | 2.7% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Analizada | Alta (8.5) | 1.5% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 18/9/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 18/9/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Modificada | Alta (8.5) | 1.6% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 30/9/2026 | An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting… | |
| Analizada | Alta (7.3) | 0.48% | 💥 PoC | Tp-link Archer Re605x Firmware | 29/1/2026 | 17/6/2026 | The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level… | |
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Archer Mr600 Firmware | 26/1/2026 | 17/6/2026 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Searcher FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Searcher for Elementor searcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Searcher for Elementor: from n/a through <= 1.0.3. |