Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 9.2% | 💥 Exploit | Cisco 7940 RouterCisco 7960 Router | 20/3/2007 | 16/6/2026 | Vulnerabilidad no especificada en el teléfono Cisco IP Phone 7940 y 7960 ejecutando el software empotrado (firmware) anterior a POS8-6-0 permite a atacantes remotos provocar una denegación de servicio a través del campo Remote-Party-ID sipURI en una petición SIP INVITE. NOTA: la procedencia de esta información es… | |
| Modificada | Media (5) | 1.2% | — | Hawking Technology Wr254-ca Wireless Router | 15/11/2006 | 16/6/2026 | Router Wireless de Hawking Technology WR254-CA utiliza un dirección IP fuertemente codificada entre el grupo de direcciones IP de los servidores DNS, lo cual podría permitir que atacantes remotos provoquen denegación de servicio o secuestren el router atacando o suplantando el servidor en las direcciones fuertemente… | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | ECI Telecom B-focus Wireless 802.11bg Adsl2+ Router | 4/11/2006 | 16/6/2026 | Router ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ permite a un atacante remoto leer ficheros de su elección a través de unas ciertas respuestas HTTP, como se demostró por una respuesta para un fichero de configuración de router, realcionado con la URI /html/defs. | |
| Modificada | Media (5) | 1.9% | — | Inca Im-204 Adsl Router | 30/10/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en /cgi-bin/webcm en INCA IM-204 permite a atacantes remotos leer archivos de su elección mediante una secuencia "/./." (punto punto modificada) en el parámetro getpage. | |
| Modificada | Media (5) | 1.8% | — | Xorp Extensible Open Router Platform | 20/10/2006 | 16/6/2026 | XORP (eXtensible Open Router Platform) 1.2 y 1.3 permite a un atacante remoto provocar denegación de servicio (caida de aplicación) a través de un Open Shortest Path First (OSPF) Link State Advertisement (LSA) con un campo de longitud LSA no válido. | |
| Modificada | Media (5) | 2.3% | — | Siemens Speedstream Wireless Router | 27/7/2006 | 16/6/2026 | Siemens SpeedStream 2624 permite a atacantes remotos provocar denegación de servicio (cuelgue de dispositivo) a través del envío de paquetes manipulados en el interface web del administrador. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | D-link Di-604 Broadband RouterD-link Di-784D-link Ebr-2310 Ethernet Broadband RouterD-link Wbr-1310 Wireless G Router+3 | 21/7/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en el servicio Universal Plug and Play (UPnP) de D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router permite a atacantes remotos ejecutar código de su elección mediante… | |
| Modificada | Alta (7.5) | 4.3% | — | Cisco Router WEB Setup | 18/7/2006 | 16/6/2026 | La configuración por defecto en el servidor IOS HTTP en Cisco Router Web Setup (CRWS) anterior a 3.3.0 construcción 31 no requiere credenciales, lo cual permite a atacantes remotos acceder al servidor con niveles de privielgio de su elección, también conocido como fallo CSCsa78190. | |
| Modificada | Media (5) | 6.7% | 💥 Exploit | BT Voyager 2091 Wireless Adsl Router | 13/7/2006 | 16/6/2026 | El firmware BT Voyager 2091 Wireless 2.21.05.08m_A2pB018c1.d16d y anteriores, y 3.01m y anteriores, permite a atacantes remotos evitar el proceso de autenticación y obtener información sensible, por ejemplo información de configuración, mediante (1) /btvoyager_getconfig.sh, credenciales PPP mediante (2)… | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Speedstream Wireless Router | 3/7/2006 | 16/6/2026 | Vulnerabilidad en el router Speedstream Wireless 2624 de Siemens permite a usuarios locales evitar la autenticación y acceder a ficheros protegidos a través del componente Universal Plug and Play UPnP/1.0. | |
| Modificada | Alta (7.5) | 1.5% | — | Sitecom Wl-153 Router FirmwareSitecom Wl-153 | 24/5/2006 | 16/6/2026 | Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | |
| Modificada | Alta (7.5) | 1.5% | — | Zyxel P-335wt Router | 24/5/2006 | 16/6/2026 | ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | |
| Modificada | Media (4.9) | 1.8% | — | Netgear Router | 7/3/2006 | 16/6/2026 | Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single… | |
| Modificada | Alta (7.8) | 3.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Router | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets. | |
| Modificada | Media (5) | 1.6% | — | Dell Truemobile 2300 Wireless Broadband Router | 8/12/2005 | 16/6/2026 | Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp. | |
| Modificada | Alta (7.5) | 1.8% | — | ECI Telecom B-focus Router | 3/8/2005 | 16/6/2026 | B-FOCuS Router 312+ permite que atacantes remotos se salten la autentificación y obtengan acceso no autorizado mediante una petición directa a firmwarecfg. | |
| Modificada | Alta (7.5) | 1.5% | — | Belkin 54G Wireless Router | 26/7/2005 | 16/6/2026 | Los rúter inalámbricos Belkin 54g no fijan adecuadamente el password de administración, lo que permite que atacantes remotos ganen acceso mediante las interfaces de administración de Telnet o de web. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 1.6% | — | Nortel ContivityNortel VPN Router 1010Nortel VPN Router 1050Nortel VPN Router 1100+5 | 27/5/2005 | 16/6/2026 | Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header. | |
| Modificada | Alta (7.5) | 1.6% | — | Arcowave Systems Wlan AP + Adsl Router | 14/5/2005 | 16/6/2026 | Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell. | |
| Modificada | Media (5) | 1.2% | — | Belkin 54G Wireless Router | 2/5/2005 | 16/6/2026 | The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Belkin 54G Wireless Router | 2/5/2005 | 16/6/2026 | Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication. | |
| Modificada | Alta (7.5) | 1.4% | — | Gigafast Ethernet Gigafast Router | 2/5/2005 | 16/6/2026 | Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext. | |
| Modificada | Media (5) | 3.2% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Media (5) | 1.6% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. |