Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.24%—ZTE Zxr10 1800-2s FirmwareZTE Zxr10 2800-4 FirmwareZTE Zxr10 3800-8 FirmwareZTE Zxr10 160 Firmware10/10/202417/6/2026
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
AnalizadaMedia (6.5)0.40%—ZTE Mf296r Firmware18/9/202417/6/2026
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.
AplazadaAlta (8.1)0.56%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid…
AplazadaCrítica (9.8)0.48%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack…
AplazadaCrítica (9.8)0.48%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An…
AplazadaAlta (8.1)0.38%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated attacker can get RCE as root by…
AnalizadaAlta (8.8)0.26%—ZTE Zxv10 Et301 FirmwareZTE Zxv10 Xt802 Firmware8/8/202417/6/2026
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
AnalizadaAlta (8.8)0.17%—ZTE Zxcloud Irai9/7/202417/6/2026
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
AnalizadaMedia (6.4)0.24%—ZTE Zxhn H388x Firmware20/6/202417/6/2026
There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.
AnalizadaMedia (6.5)0.46%—ZTE Zxun-epdg14/5/202417/6/2026
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session…
AplazadaMedia (5.4)0.46%—Aazztech Post SliderAI26/4/202417/6/2026
Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7.
ModificadaMedia (6.1)0.32%—ZTE Mf258 Firmware10/1/202417/6/2026
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
ModificadaMedia (4.8)0.20%—ZTE Zxcloud Irai5/1/202417/6/2026
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.
ModificadaMedia (5.5)0.17%—ZTE Redmagic 8 PRO Firmware4/1/202417/6/2026
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
ModificadaAlta (7.8)0.61%—ZTE Zxcloud Irai3/1/202417/6/2026
There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.
ModificadaAlta (7.8)0.22%—ZTE Zxcloud Irai3/1/202417/6/2026
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.
ModificadaMedia (5.5)0.15%—ZTE Zxcloud Irai3/1/202417/6/2026
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.
ModificadaAlta (7.8)0.16%—ZTE Zxcloud Irai3/1/202417/6/2026
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
ModificadaSin puntuar0.27%—Yaztekteknoloji E-commerce29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: through 20231229. NOTE: The vendor was contacted early about this disclosure but did…
ModificadaAlta (7.5)0.70%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
ModificadaAlta (8.8)1.8%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
ModificadaMedia (6.5)0.51%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
ModificadaAlta (8)0.34%—ZTE Mf833u1 FirmwareZTE Mf286r Firmware14/12/202317/6/2026
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.
ModificadaMedia (6.5)0.59%—ZTE Zxcloud Irai14/12/202317/6/2026
There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.
ModificadaAlta (7.8)0.21%—ZTE Zxcloud Irai14/12/202317/6/2026
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
Orbitaley — Vulnerabilidades