Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Jd12lAI | 29/6/2026 | 29/6/2026 | A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Jd12lAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Jd12lAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (4.6) | 0.15% | — | Tenda N300 F3AI | 26/6/2026 | 29/6/2026 | Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via… | |
| Analizada | Crítica (9.8) | 0.84% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. | |
| Aplazada | Alta (7.6) | 0.31% | — | Sukimalab Attendance ManagerAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Tenda 5g03AI | 15/6/2026 | 17/6/2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. | |
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Shenzhen Tenda Technology W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 20/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Shenzhen Tenda Technology W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. |