Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 44% | 💥 Exploit | Chiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 FirmwareChiyu-tech Semac D2 FirmwareChiyu-tech Semac D4 Firmware+7 | 1/6/2021 | 17/6/2026 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it… | |
| Modificada | Media (6.1) | 5.1% | — | Chiyu-tech Bf-430 FirmwareChiyu-tech Bf-431 FirmwareChiyu-tech Bf-450m FirmwareChiyu-tech Semac S2 Firmware+11 | 1/6/2021 | 17/6/2026 | An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | Zyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+26 | 22/12/2020 | 17/6/2026 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+23 | 4/3/2020 | 17/6/2026 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI… | |
| Modificada | Crítica (9.8) | 3.7% | — | Belkin N300 Firmware | 7/2/2020 | 16/6/2026 | An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging." | |
| Modificada | Crítica (9.1) | 44% | 💥 Exploit | Zyxel Uag2100 FirmwareZyxel Uag4100 FirmwareZyxel Uag5100 FirmwareZyxel Usg110 Firmware+10 | 27/6/2019 | 17/6/2026 | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service. | |
| Modificada | Media (6.1) | 21% | 💥 Exploit | Zyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp800 FirmwareZyxel Usg20-vpn Firmware+17 | 22/4/2019 | 17/6/2026 | On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter. | |
| Modificada | Media (4.6) | 1.1% | 💥 PoC | HP 240 G1 FirmwareHP 245 G1 FirmwareHP 1000-1300 FirmwareHP 250 G1 Notebook PC Firmware+30 | 3/10/2018 | 17/6/2026 | A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014. | |
| Modificada | Alta (7.5) | 2.7% | — | ABB Vsn300 FirmwareABB Vsn300 FOR React Firmware | 7/8/2017 | 17/6/2026 | An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and… | |
| Modificada | Media (6.5) | 1.5% | — | ABB Vsn300 FirmwareABB Vsn300 FOR React Firmware | 7/8/2017 | 17/6/2026 | A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to… | |
| Modificada | Crítica (9.8) | 5.6% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 18/7/2017 | 17/6/2026 | Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100,… | |
| Modificada | Alta (7.8) | 1.8% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 17/7/2017 | 17/6/2026 | Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,… | |
| Modificada | Alta (7.8) | 2.8% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 17/7/2017 | 17/6/2026 | Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,… | |
| Modificada | Alta (8.3) | 2.3% | — | Belkin N300 FirmwareBelkin N300 | 29/9/2014 | 16/6/2026 | The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header. | |
| Modificada | Media (6.8) | 0.61% | — | Belkin N300 FirmwareBelkin N300 | 29/9/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration. |