Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function. | |
| Modificada | Crítica (9.8) | 1.8% | — | Tenda AC9 Firmware | 24/2/2022 | 17/6/2026 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi. | |
| Modificada | Crítica (9.8) | 1.8% | — | Tenda AC9 Firmware | 24/2/2022 | 17/6/2026 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo. | |
| Modificada | Crítica (9.8) | 10% | — | Tenda AC9 Firmware | 24/2/2022 | 17/6/2026 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. | |
| Modificada | Crítica (9.8) | 3.8% | — | Tenda AC9 Firmware | 11/2/2022 | 17/6/2026 | A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request. | |
| Modificada | Alta (7.2) | 28% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system. | |
| Modificada | Alta (8.2) | 33% | — | Dell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure. | |
| Modificada | Alta (8.1) | 30% | — | Dell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data… | |
| Modificada | Alta (8.8) | 1.1% | — | Tendacn AC9 Firmware | 29/10/2021 | 9/7/2026 | Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter. | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Tendacn AC9 Firmware | 29/10/2021 | 9/7/2026 | Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter. | |
| Modificada | Crítica (9.8) | 4.2% | — | Tendacn Ac10u FirmwareTendacn AC9 Firmware | 29/10/2021 | 17/6/2026 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. | |
| Modificada | Alta (7.2) | 2.9% | — | Tendacn AC9 Firmware | 30/9/2021 | 17/6/2026 | A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg. | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Media (4.3) | 0.69% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate. | |
| Modificada | Media (6.1) | 0.81% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. | |
| Modificada | Media (6.1) | 0.81% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Crítica (10) | 1.7% | — | Dell Idrac9 Firmware | 29/7/2021 | 17/6/2026 | Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console. | |
| Modificada | Baja (2.7) | 0.92% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user. | |
| Modificada | Media (4.8) | 0.63% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access… | |
| Modificada | Media (4.8) | 0.40% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.10.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected while generating a certificate. When… |