Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.66%—Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+463/9/202417/6/2026
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
AnalizadaMedia (5.5)0.14%—Zyxel Lte3202-m437 FirmwareZyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 Firmware+6121/5/202417/6/2026
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
AplazadaMedia (5.7)0.40%—Nebulab SolidusAI14/5/202417/6/2026
Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.
ModificadaAlta (7.5)0.84%—Vesoft Nebulagraph Studio1/9/20239/7/2026
Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.
ModificadaCrítica (9.8)2.6%💥 PoCNexxtsolutions Nebula1200-ac Firmware6/7/202317/6/2026
Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.
ModificadaMedia (6.5)1.0%—Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nr7101 FirmwareZyxel Nebula Nr7101 Firmware5/6/202317/6/2026
A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could allow a remote authenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
ModificadaMedia (6.5)0.62%—Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+4411/1/202317/6/2026
A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.
ModificadaMedia (6.5)0.72%—Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+4411/1/202317/6/2026
A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.
ModificadaAlta (8.8)1.1%—Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+3511/1/202317/6/2026
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
ModificadaCrítica (9.8)0.61%—Zyxel Lte3202-m437 FirmwareZyxel Lte3316-m604 FirmwareZyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 Firmware+1311/1/202317/6/2026
A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
ModificadaAlta (7.5)0.56%—Opennebula28/10/202217/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.
ModificadaCrítica (9.8)1.6%—Opennebula28/10/202217/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
ModificadaMedia (6.5)0.78%—Opennebula28/10/202217/6/2026
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
ModificadaMedia (4.3)0.39%—Nebulab Solidus1/6/202217/6/2026
solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a…
ModificadaMedia (4.3)0.57%—Nebulab Solidus20/12/202117/6/2026
`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5,…
ModificadaAlta (7.5)1.4%—Nebulab Solidus7/12/202117/6/2026
Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through…
ModificadaAlta (8.8)0.73%—Nebulab Solidus Auth Devise17/11/202117/6/2026
solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `solidus_auth_devise` are…
ModificadaMedia (5.3)0.90%—Nebulab Solidus4/8/202017/6/2026
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipment costs…
ModificadaAlta (8.8)3.4%—Slack Nebula2/4/202017/6/2026
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistence or to bypass…
ModificadaAlta (7.5)1.2%—Anker Nebula Capsule Projector FirmwareAnker Nebula Capsule Projector8/12/201817/6/2026
Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system) via a crafted application that sends data to WifiService.
Orbitaley — Vulnerabilidades