Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.81% | — | Buffalo Wzr-1750dhp2 Firmware | 9/4/2018 | 17/6/2026 | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.70% | — | Buffalo Wxr-1900dhp2 Firmware | 9/3/2018 | 17/6/2026 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.3% | — | Buffalo Wxr-1900dhp2 Firmware | 9/3/2018 | 17/6/2026 | Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a specially crafted file. | |
| Modificada | Alta (8.8) | 0.81% | — | Buffalo Wxr-1900dhp2 Firmware | 9/3/2018 | 17/6/2026 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. | |
| Modificada | Media (6.5) | 1.4% | — | Buffalo Wzr-600dhp3 FirmwareBuffalo Hw-450hp-zwe FirmwareBuffalo Wzr-hp-g450h FirmwareBuffalo Wzr-450hp Firmware+30 | 19/6/2016 | 17/6/2026 | BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Buffalo Wzr-900dhp2 FirmwareBuffalo Wzr-600dhp3 FirmwareBuffalo Wzr-s900dhp FirmwareBuffalo Wzr-s600dhp Firmware+2 | 19/6/2016 | 17/6/2026 | Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | Buffalotech Wmr-300 FirmwareBuffalotech Wex-300 FirmwareBuffalotech Wmr-433 FirmwareBuffalotech Bhr-4grv2 Firmware+4 | 22/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices… | |
| Modificada | Alta (8.8) | 0.54% | — | Buffalotech Whr-1166dhp FirmwareBuffalotech Whr-300hp2 FirmwareBuffalotech Wmr-300 FirmwareBuffalotech Bhr-4grv2 Firmware+4 | 22/1/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300… | |
| Modificada | Alta (7.7) | 1.1% | — | Buffalotech Wsr-600dhp FirmwareBuffalotech Whr-300hp2 FirmwareBuffalotech Whr-1166dhp FirmwareBuffalotech Bhr-4grv2 Firmware+3 | 9/6/2015 | 17/6/2026 | The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS commands via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dlink Dir-905l FirmwareDlink Dir-605l FirmwareDlink Dir-600l FirmwareDlink Dir-619l Firmware+22 | 1/5/2015 | 17/6/2026 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |