Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 14% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 6/8/2024 | 17/6/2026 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability. | |
| Analizada | Media (6.5) | 0.32% | — | Zyxel Nwa50ax FirmwareZyxel Nwa50ax-pro FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+16 | 23/7/2024 | 17/6/2026 | The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device. | |
| Modificada | Alta (8.8) | 1.4% | — | Dlink Dir-823x Ax3000 Firmware | 8/7/2024 | 17/6/2026 | D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings. | |
| Analizada | Media (5.1) | 7.9% | — | Ruijie Rg-uac 6000-e20c FirmwareRuijie Rg-uac 6000-e20m FirmwareRuijie Rg-uac 6000-e50 FirmwareRuijie Rg-uac 6000-e50c Firmware+23 | 25/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.1) | 7.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 25/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/vpn/autovpn/online_check.php. The manipulation of the argument peernode leads to os command injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.1) | 7.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 25/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown function of the file /view/vpn/autovpn/online.php. The manipulation of the argument peernode leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.1) | 9.0% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 25/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown processing of the file /view/systemConfig/sys_user/user_commit.php. The manipulation of the argument email2/user_name leads to os command injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Media (5.1) | 9.0% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 25/5/2024 | 17/6/2026 | A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects the function addVlan of the file /view/networkConfig/vlan/vlan_add_commit.php. The manipulation of the argument phyport leads to os command injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Alta (7.2) | 0.73% | — | Asus ExpertwifiAIAsus Rt-ax55AIAsus Rt-ax58uAIAsus Rt-ac67uAI+6 | 20/5/2024 | 17/6/2026 | ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS… | |
| Analizada | Media (5.3) | 6.4% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 14/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The manipulation of the argument name/remote/local/IP leads to os command injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.3) | 6.4% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 14/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/viewData/detail.php. The manipulation of the argument filename leads to os command injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.3) | 6.4% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 14/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argument oldipmask/oldgateway leads to os command injection. The… | |
| Analizada | Media (5.3) | 6.4% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 14/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Alta (7.2) | 7.1% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/networkConfig/ArpTable/arp_add_commit.php. The manipulation of the argument text_ip_addr/text_mac_addr leads to os command injection. The attack may be… | |
| Analizada | Alta (7.2) | 6.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely.… | |
| Analizada | Alta (7.2) | 7.1% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevname leads to os command injection. It is possible to launch the… | |
| Analizada | Alta (7.2) | 7.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The manipulation of the argument text_prefixlen/text_gateway/devname leads to os command injection. The attack may be… | |
| Analizada | Alta (7.2) | 7.6% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The manipulation of the argument prelen/ethname leads to os command injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Alta (7.2) | 6.7% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. The manipulation of the argument peer_ip/local_ip leads to os command injection. The attack may be launched remotely.… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation of the argument ifName leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 5.0% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 27/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os command injection. The attack may be initiated remotely. The exploit… | |
| Aplazada | Alta (7.5) | 0.51% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… |