Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Wavlink Wn572hp3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn530h4 FirmwareWavlink Wn535g3 Firmware+1 | 10/8/2022 | 17/6/2026 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled and blockSynFloodEnabled, which leads to command injection in page /man_security.shtml. | |
| Modificada | Crítica (9.8) | 2.3% | — | Wavlink Wn572hp3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn530h4 FirmwareWavlink Wn535g3 Firmware+1 | 10/8/2022 | 17/6/2026 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml. | |
| Modificada | Crítica (9.8) | 2.3% | — | Wavlink Wn572hp3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn530h4 FirmwareWavlink Wn535g3 Firmware+1 | 10/8/2022 | 17/6/2026 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to command injection in page /cli_black_list.shtml. | |
| Modificada | Crítica (9.8) | 1.5% | — | Wavlink Wn572hp3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn530h4 FirmwareWavlink Wn535g3 Firmware+1 | 10/8/2022 | 17/6/2026 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml. | |
| Modificada | Alta (8.8) | 2.2% | — | Wavlink Wn572hp3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn530h4 FirmwareWavlink Wn535g3 Firmware+1 | 10/8/2022 | 17/6/2026 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, which leads to command injection in page /wizard_router_mesh.shtml. | |
| Modificada | Media (6.1) | 6.7% | 💥 Exploit | Wavlink Wn533a8 Firmware | 20/7/2022 | 17/6/2026 | Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Wavlink Wn533a8 Firmware | 20/7/2022 | 17/6/2026 | An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);]. | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Wavlink Wn530hg4 FirmwareWavlink Wn531g3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn551k1 Firmware | 7/5/2020 | 17/6/2026 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a… | |
| Modificada | Alta (7.5) | 1.8% | — | Wavlink Wl-wn579g3 FirmwareWavlink Wl-wn575a3 FirmwareWavlink Wl-wn530hg4 FirmwareWavlink Wn531g3 Firmware+11 | 27/4/2020 | 17/6/2026 | An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any… | |
| Modificada | Media (6.8) | 0.34% | — | Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+144 | 19/8/2019 | 17/6/2026 | A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware. | |
| Modificada | Media (5.9) | 1.0% | — | Chuango H4 Plus FirmwareChuango AWV Plus FirmwareChuango G5W 3G FirmwareChuango G5 Plus Firmware+6 | 8/5/2019 | 17/6/2026 | The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as… | |
| Modificada | Alta (7.5) | 3.4% | — | ABB Pm554-tp-eth FirmwarePhoenixcontact ILC 151 ETH FirmwareSchneider-electric Modicon M221 FirmwareSiemens 6es7211-1ae40-0xb0 Firmware+6 | 17/4/2019 | 17/6/2026 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |