Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.60% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Ac10AI | 20/7/2026 | 20/7/2026 | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Tenda Ac10AI | 15/7/2026 | 16/7/2026 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 14/7/2026 | A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 15/7/2026 | A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 14/7/2026 | A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 14/7/2026 | A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 14/7/2026 | A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Be12 PROAI | 14/7/2026 | 15/7/2026 | A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Ch22AI | 13/7/2026 | 13/7/2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.1) | 0.33% | — | Akpali9 Attendance-management-systemAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date results in cross site scripting. It is possible to initiate the attack remotely.… | |
| Analizada | Alta (8.1) | 0.43% | — | Flag Attendance Field Project Flag Attendance Field | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. | |
| Aplazada | Alta (7.5) | 0.46% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior… | |
| Aplazada | Alta (7.5) | 0.57% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request. | |
| Aplazada | Alta (7.5) | 0.57% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request. | |
| Aplazada | Alta (7.5) | 0.56% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID,… | |
| Aplazada | Alta (7.5) | 0.56% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP… | |
| Aplazada | Alta (7.5) | 0.57% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY… | |
| Aplazada | Alta (7.5) | 0.57% | — | Tenda CP3AI | 9/7/2026 | 10/7/2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiting state, causing the… | |
| Aplazada | Media (6.5) | 1.1% | — | Tenda Ac18AI | 1/7/2026 | 2/7/2026 | An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Jd12lAI | 29/6/2026 | 29/6/2026 | A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Jd12lAI | 29/6/2026 | 30/6/2026 | A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |