Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Tenda AC9 Firmware18/3/202217/6/2026
Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.
ModificadaCrítica (9.8)1.7%—Tenda AC9 Firmware18/3/202217/6/2026
Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.
ModificadaCrítica (9.8)1.7%—Tenda AC9 Firmware18/3/202217/6/2026
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.
ModificadaCrítica (9.8)1.7%—Tenda AC9 Firmware18/3/202217/6/2026
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
ModificadaCrítica (9.8)1.8%—Tenda AC9 Firmware24/2/202217/6/2026
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
ModificadaCrítica (9.8)1.8%—Tenda AC9 Firmware24/2/202217/6/2026
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
ModificadaCrítica (9.8)10%—Tenda AC9 Firmware24/2/202217/6/2026
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
ModificadaCrítica (9.8)3.8%—Tenda AC9 Firmware11/2/202217/6/2026
A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.
ModificadaAlta (7.2)28%—Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware23/11/202117/6/2026
Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.
ModificadaAlta (8.2)33%—Dell EMC Idrac9 Firmware23/11/202117/6/2026
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure.
ModificadaAlta (8.1)30%—Dell EMC Idrac9 Firmware23/11/202117/6/2026
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data…
ModificadaAlta (8.8)1.1%—Tendacn AC9 Firmware29/10/20219/7/2026
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.
ModificadaAlta (8.8)1.1%💥 PoCTendacn AC9 Firmware29/10/20219/7/2026
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.
ModificadaCrítica (9.8)4.2%—Tendacn Ac10u FirmwareTendacn AC9 Firmware29/10/202117/6/2026
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
ModificadaAlta (7.2)2.9%—Tendacn AC9 Firmware30/9/202117/6/2026
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
ModificadaMedia (6.1)0.75%—Dell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
ModificadaMedia (4.3)0.69%—Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
ModificadaMedia (6.1)0.81%—Dell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.
ModificadaMedia (6.1)0.81%—Dell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.
ModificadaMedia (6.1)0.75%—Dell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
ModificadaMedia (6.1)0.75%—Dell EMC Idrac9 Firmware3/8/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
ModificadaCrítica (10)1.7%—Dell Idrac9 Firmware29/7/202117/6/2026
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console.
ModificadaBaja (2.7)0.92%—Dell Idrac9 Firmware30/4/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.
ModificadaMedia (4.8)0.63%—Dell Idrac9 Firmware30/4/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access…
ModificadaMedia (4.8)0.40%—Dell Idrac9 Firmware30/4/202117/6/2026
Dell EMC iDRAC9 versions prior to 4.40.10.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected while generating a certificate. When…