Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Adcon Telemetry A850 Telemetry Gateway Base Station Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Adcon Telemetry A850 Telemetry Gateway Base Station. The Web Interface does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output; this could allow for cross-site scripting. | |
| Modificada | Alta (8.1) | 4.1% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain… | |
| Modificada | Crítica (9.8) | 5.2% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory… | |
| Modificada | Crítica (9.8) | 3.9% | — | Apple Airport Base Station Firmware | 3/7/2016 | 17/6/2026 | Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.8% | — | Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+1 | 26/6/2016 | 17/6/2026 | The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.5% | — | Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+1 | 26/6/2016 | 17/6/2026 | Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function. | |
| Modificada | Alta (8.6) | 2.2% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors. | |
| Modificada | Alta (8.6) | 1.5% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (8.7) | 1.3% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support. | |
| Modificada | Crítica (10) | 2.5% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Qnap Photo Station FirmwareQnap Photo Station | 9/6/2014 | 16/6/2026 | QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 7/1/2014 | 17/6/2026 | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 7/1/2014 | 17/6/2026 | CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task. | |
| Modificada | Media (6.8) | 2.5% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 17/12/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 17/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Media (5.4) | 1.1% | — | Apple Airport Base Station Firmware | 8/9/2013 | 16/6/2026 | Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame. | |
| Modificada | Alta (7.1) | 1.4% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write… | |
| Modificada | Media (6.1) | 0.82% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and… | |
| Modificada | Alta (10) | 4.2% | — | Cisco Unified IP Conference Station 7935 FirmwareCisco Unified IP Conference Station Firmware 7936 | 22/2/2007 | 16/6/2026 | The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time |