Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.66% | — | Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+46 | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Analizada | Media (5.5) | 0.14% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 Firmware+61 | 21/5/2024 | 17/6/2026 | The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. | |
| Aplazada | Media (5.7) | 0.40% | — | Nebulab SolidusAI | 14/5/2024 | 17/6/2026 | Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL. | |
| Modificada | Alta (7.5) | 0.84% | — | Vesoft Nebulagraph Studio | 1/9/2023 | 9/7/2026 | Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Nexxtsolutions Nebula1200-ac Firmware | 6/7/2023 | 17/6/2026 | Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET. | |
| Modificada | Media (6.5) | 1.0% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nr7101 FirmwareZyxel Nebula Nr7101 Firmware | 5/6/2023 | 17/6/2026 | A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could allow a remote authenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Modificada | Media (6.5) | 0.62% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. | |
| Modificada | Media (6.5) | 0.72% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.1% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+35 | 11/1/2023 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 0.61% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3316-m604 FirmwareZyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 Firmware+13 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device. | |
| Modificada | Alta (7.5) | 0.56% | — | Opennebula | 28/10/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | |
| Modificada | Crítica (9.8) | 1.6% | — | Opennebula | 28/10/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | |
| Modificada | Media (6.5) | 0.78% | — | Opennebula | 28/10/2022 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. | |
| Modificada | Media (4.3) | 0.39% | — | Nebulab Solidus | 1/6/2022 | 17/6/2026 | solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a… | |
| Modificada | Media (4.3) | 0.57% | — | Nebulab Solidus | 20/12/2021 | 17/6/2026 | `solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5,… | |
| Modificada | Alta (7.5) | 1.4% | — | Nebulab Solidus | 7/12/2021 | 17/6/2026 | Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through… | |
| Modificada | Alta (8.8) | 0.73% | — | Nebulab Solidus Auth Devise | 17/11/2021 | 17/6/2026 | solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `solidus_auth_devise` are… | |
| Modificada | Media (5.3) | 0.90% | — | Nebulab Solidus | 4/8/2020 | 17/6/2026 | In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipment costs… | |
| Modificada | Alta (8.8) | 3.4% | — | Slack Nebula | 2/4/2020 | 17/6/2026 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistence or to bypass… | |
| Modificada | Alta (7.5) | 1.2% | — | Anker Nebula Capsule Projector FirmwareAnker Nebula Capsule Projector | 8/12/2018 | 17/6/2026 | Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system) via a crafted application that sends data to WifiService. |