Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.2%—Gigafast Ethernet Gigafast Router20/2/200516/6/2026
Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.
ModificadaAlta (7.2)1.3%💥 ExploitIsync Mrouter22/1/200516/6/2026
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.
ModificadaMedia (5)2.3%—Cisco IOSCisco Multiservice Platform 2650Cisco Multiservice Platform 2650xmCisco Multiservice Platform 2651+610/1/200516/6/2026
Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple…
ModificadaMedia (5)3.1%💥 ExploitConceptronic Cadslr1 Adsl Router31/12/200416/6/2026
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.
ModificadaMedia (6.4)1.7%—Zonet Zsr1104we Wireless Router Runtime Code31/12/200416/6/2026
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.
ModificadaAlta (7.5)1.7%—Sweex Wireless Broadband Router Accesspoint 802.11g31/12/200416/6/2026
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
ModificadaMedia (4.3)1.9%💥 ExploitEdimax Full Rate Adsl Router31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.
ModificadaAlta (7.5)1.7%—Edimax Full Rate Adsl Router31/12/200416/6/2026
The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.
ModificadaMedia (5)3.0%💥 ExploitBT Voyager 2000 Wireless Adsl Router6/12/200416/6/2026
El encaminador ADSL inalámbrico BT Voyager 2000 tiene un nombre de comunidad SNMP público por defecto, lo que permite a atacantes remotos obtener información sensible, como la contraseña, que se almacena en texto claro.
ModificadaAlta (7.5)1.5%—Hawking Technology Har11a DSL Router26/10/200416/6/2026
The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.
ModificadaAlta (7.5)1.7%—X-micro Wlan 11B Broadband Router Firmware10/4/200416/6/2026
X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.
ModificadaAlta (7.5)2.4%—X-micro Wlan 11B Broadband Router Firmware10/4/200416/6/2026
X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.
ModificadaAlta (7.5)4.4%—Cisco Application AND Content Networking SoftwareCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content Distribution Manager 4670+55/1/200416/6/2026
Desbordamiento de búfer en el módulo de autenticación de Cisco ACNS 4.x anteriores a 4.2.11, y 5.x anteriores a 5.0.5, permite a atacantes remotos ejecutar código arbitrario mediante una contraseña larga.
ModificadaAlta (7.5)5.1%—Iptel SIP Express Router31/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaMedia (5)1.8%—Efficient Networks 5861 DSL Router31/12/200316/6/2026
Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap.
ModificadaMedia (5)1.4%—SMC Networks Barricade Wireless Cable DSL Broadband Router24/7/200316/6/2026
El encaminador de banda ancha inalámbrico para cable y DSL SMC Networks Barricade SMC7004VWBR permite a atacantes remotos causar una denegación de servicio mediante ciertos paquetes al puerto PPTP 1723 en el interfaz interno.
ModificadaAlta (7.5)2.4%—Belkin F5d5230-4 4-port Cable DSL Gateway Router11/4/200316/6/2026
El enrutador Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 sustituye la dirección IP de origen de paquetes internos con la del interfaz externo del router cuando reenvia una petición de una máquina interna a un servidor web interno, lo que permite a atacantes remotos esconder que máquina está siendo usado…
ModificadaAlta (10)2.3%—Telindus 1120 Adsl Router31/12/200216/6/2026
Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password.
ModificadaAlta (7.5)1.6%—DUG Song DsniffDUG Song FragrouteDUG Song Fragrouter31/12/200216/6/2026
configure for Dsniff 2.3, fragroute 1.2, and fragrouter 1.6, when downloaded from monkey.org on May 17, 2002, has been modified to contain a backdoor, which allows remote attackers to access the system.
ModificadaMedia (5)1.4%—Lucent Ascend MAX RouterLucent Ascend Pipeline RouterLucent Dslterminator31/12/200216/6/2026
Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information…
ModificadaMedia (5)3.4%💥 ExploitLucent Access Point Service Router 1500Lucent Access Point Service Router 300Lucent Access Point Service Router 60031/12/200216/6/2026
Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrative interface.
ModificadaMedia (5)2.5%—Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+84/11/200216/6/2026
Implementaciones de IPSEC, incluyendo FreeS/WAN y KAME no calculan adecuadamente la longitud de los datos de autenticación, lo que permite a atacantes remotos causar una denegación de servicio (kernel panic) mediante paquetes Encapsulating Security Payload (EPS) cortos falsificados, lo que resulta en errores de…
ModificadaAlta (7.5)2.9%💥 ExploitTelindus Adsl Router4/10/200216/6/2026
Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext.
ModificadaAlta (7.5)1.6%—Cisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content EngineCisco Enterprise Content Delivery Network Software+412/8/200216/6/2026
The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.
ModificadaMedia (5)1.9%—Mrtg Multi Router Traffic Grapher CGI29/5/200216/6/2026
Vulnerabilidad de atravesamiento de directorios en Multi Router Traffic Grapher (MRTG) permite a atacantes remotos leer ficheros arbitrarios mediante un .. (punto punto) en el parámetro cfg de 14all.cgi14all-1.1.cgitraffic.cgi, o mrtg.cgi