Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.83%—Adcon Telemetry A850 Telemetry Gateway Base Station Firmware13/2/201717/6/2026
An issue was discovered in Adcon Telemetry A850 Telemetry Gateway Base Station. The Web Interface does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output; this could allow for cross-site scripting.
ModificadaAlta (8.1)4.1%—Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware4/1/201717/6/2026
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain…
ModificadaCrítica (9.8)5.2%—Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware4/1/201717/6/2026
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory…
ModificadaCrítica (9.8)3.9%—Apple Airport Base Station Firmware3/7/201617/6/2026
Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaCrítica (9.8)4.8%—Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+126/6/201617/6/2026
The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.
ModificadaCrítica (9.8)2.5%—Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+126/6/201617/6/2026
Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function.
ModificadaAlta (8.6)2.2%—Adcon A840 Telemetry Gateway Base Station Firmware24/12/201517/6/2026
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors.
ModificadaAlta (8.6)1.5%—Adcon A840 Telemetry Gateway Base Station Firmware24/12/201517/6/2026
Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (8.7)1.3%—Adcon A840 Telemetry Gateway Base Station Firmware24/12/201517/6/2026
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.
ModificadaCrítica (10)2.5%—Adcon A840 Telemetry Gateway Base Station Firmware24/12/201517/6/2026
Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
ModificadaMedia (5)1.3%—Qnap Photo Station FirmwareQnap Photo Station9/6/201416/6/2026
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
ModificadaAlta (10)10%💥 ExploitCru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation7/1/201417/6/2026
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
ModificadaAlta (10)13%💥 ExploitCru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation7/1/201417/6/2026
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.
ModificadaMedia (6.8)2.5%💥 ExploitCru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation17/12/201317/6/2026
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors.
ModificadaMedia (4.3)3.5%💥 ExploitCru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation17/12/201317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified…
ModificadaMedia (5.4)1.1%—Apple Airport Base Station Firmware8/9/201316/6/2026
Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame.
ModificadaAlta (7.1)1.4%—Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+122/12/201016/6/2026
Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply.
ModificadaBaja (2.6)1.7%—Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+122/12/201016/6/2026
The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write…
ModificadaMedia (6.1)0.82%—Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+122/12/201016/6/2026
The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and…
ModificadaAlta (10)4.2%—Cisco Unified IP Conference Station 7935 FirmwareCisco Unified IP Conference Station Firmware 793622/2/200716/6/2026
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time