Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—NEC Sv8100 FirmwareNEC Sv9100 FirmwareNEC Sl1100 FirmwareNEC Sl2100 Firmware29/7/202017/6/2026
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
ModificadaCrítica (9.8)1.3%—Netgear Mr1100 Firmware15/4/202017/6/2026
NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.
ModificadaAlta (7.5)0.97%—Netgear Mr1100 Firmware15/4/202017/6/2026
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.
ModificadaMedia (6.5)0.88%—Netgear Mr1100 Firmware15/4/202017/6/2026
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.
ModificadaCrítica (9.8)4.4%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 50016/3/202017/6/2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could…
ModificadaAlta (7.5)4.0%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 50016/3/202017/6/2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller…
ModificadaAlta (7.5)2.8%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 50016/3/202017/6/2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.
ModificadaBaja (3.3)0.41%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 50016/3/202017/6/2026
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+234/3/202017/6/2026
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI…
ModificadaMedia (5.3)16%💥 ExploitDlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+1328/1/202016/6/2026
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU,…
ModificadaAlta (7.5)15%💥 ExploitDlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+1328/1/202016/6/2026
An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO,…
ModificadaMedia (5.3)13%💥 ExploitDlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+1328/1/202016/6/2026
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02,…
ModificadaCrítica (9.8)40%💥 ExploitDlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+1328/1/202016/6/2026
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00,…
ModificadaCrítica (9.8)2.7%—Netgear Mr1100 Firmware14/8/201917/6/2026
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.
ModificadaAlta (8.1)0.69%—Netgear Mr1100 Firmware14/8/201917/6/2026
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the…
ModificadaAlta (8.8)3.8%—Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device provide a username and password. However, the device allows D-Link apps on the mobile devices and desktop to communicate with the device without any authentication. As a part of that communication,…
ModificadaAlta (8.8)12%—Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications…
ModificadaCrítica (9.8)3.9%—Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address…
ModificadaAlta (8.8)10%—Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications…
ModificadaAlta (8.8)5.7%—Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /var/www/video folder. It seems that this binary dumps the HTTP VERB in the system logs. As a part of doing that it retrieves the HTTP VERB sent by the user and uses a vulnerable sprintf function at…
ModificadaAlta (7.8)1.7%—Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary orthrus in /sbin folder of the device handles all the UPnP connections received by the device. It seems that the binary performs a sprintf operation at address 0x0000A3E4 with the value in the command line parameter "-f" and stores it on the…
ModificadaCrítica (9.8)5.6%—Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operation at address 0x00011E34 with the value sent in the "Authorization: Basic" RTSP header and stores it…
ModificadaAlta (7.5)2.7%—Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware2/7/201917/6/2026
An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary loads at address 0x00012CF4 a flag called "Authenticate" that indicates whether a user should be authenticated or not before…
ModificadaMedia (6.1)6.4%💥 ExploitZyxel Uag2100 FirmwareZyxel Uag4100 FirmwareZyxel Uag5100 FirmwareZyxel Usg110 Firmware+527/6/201917/6/2026
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
ModificadaCrítica (9.1)44%💥 ExploitZyxel Uag2100 FirmwareZyxel Uag4100 FirmwareZyxel Uag5100 FirmwareZyxel Usg110 Firmware+1027/6/201917/6/2026
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Orbitaley — Vulnerabilidades