Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1064 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.52% | — | Tenda O3 Wireless RouterAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Media (6.5) | 0.32% | — | Tenda W3 Wireless RouterAI | 9/6/2026 | 20/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the param_1 parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Media (6.5) | 0.27% | — | Tenda W3 Wireless RouterAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Media (6.5) | 0.27% | — | Tenda W3 Wireless RouterAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Tenda W3 Wireless RouterAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private or blocking profile… | |
| Aplazada | Media (6.9) | 0.44% | — | Namelessmc Nameless MCAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reaction details. This… | |
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 22/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to… | |
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only… | |
| Aplazada | Media (5.4) | 0.13% | — | NamelessmcAI | 2/6/2026 | 22/7/2026 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization code. This allows an attacker to capture a valid OAuth callback URL for their own account and cause a victim's browser to… | |
| Aplazada | Alta (7.1) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled `post` ID and returns its content. The backend helper in `modules/Forum/classes/Forum.php` does not enforce forum or… | |
| Aplazada | Media (4.3) | 0.30% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response without proper… | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+183 | 1/6/2026 | 22/7/2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Media (6.4) | 0.32% | — | Endless ScrollAI | 27/5/2026 | 17/6/2026 | The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject… | |
| Analizada | Alta (7.3) | 0.30% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all… | |
| Analizada | Media (5) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary JavaScript code within the context of the WDU webpage. Full administrator level access to the device is possible. To… | |
| Analizada | Crítica (9.3) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this… | |
| Analizada | Alta (7.5) | 0.39% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesystem is enabled.… | |
| Aplazada | Media (5.1) | 0.29% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations. | |
| Aplazada | Media (5.1) | 0.33% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken. | |
| Aplazada | Media (4.8) | 0.25% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser. |