Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1174 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Zyxel Prestige 660Zyxel Prestige 661Zyxel Zynos26/3/200816/6/2026
Los routers ZyXEL Prestige, incluyendo los modelos P-660, P-661 y P-662 con firmware 3.40(PE9) y 3.40(AGD.2) hasta la 3.40(AHQ.3), soportan autenticación sobre HTML a través de una cadena hash en el campo hiddenPassword, lo cual permite a atacantes remotos obtener acceso mediante un ataque por repetición.
ModificadaMedia (5)1.2%—Zyxel Prestige 660Zyxel Prestige 661Zyxel Zynos26/3/200816/6/2026
Los routers ZyXEL Prestige, incluyendo los modelos P-660, P-661 y P-662 con firmware 3.40(AGD.2) hasta la 3.40(AHQ.3), permite a usuarios remotos autenticados obtener credenciales ISP y Dynamic DNS mediante el envío de una petición directa para (1) WAN.html, (2) wzPPPOE.html y (3) rpDyDNS.html leyendo así el código…
ModificadaMedia (5)1.2%—Zyxel Prestige 660Zyxel Prestige 661Zyxel Zynos26/3/200816/6/2026
Los routers ZyXEL Prestige tienen un mínimo de longitud de contraseña para la cuenta admin que es demasiado pequeña, lo cual facilita a los atacantes remotos adivinar contraseñas mediante métodos de fuerza bruta.
ModificadaAlta (9.3)1.4%💥 ExploitDetodas COM Restaurante24/3/200816/6/2026
Vulnerabilidad de inyección SQL en el componente Detodas Restaurante (com_restaurante) 1.0 para Mambo y Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id en una acción detail (detalle) a index.php, un producto distinto a CVE-2008-0562.
ModificadaMedia (6.8)1.2%—Restaurant Management System1/10/200716/6/2026
Múltiples vulnerabilidades de inclusión remota de archivo en PHP en Thierry Leriche REstaurant Management System (ReMaSys) 0.5 permiten a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro (1) DIR_ROOT de (a) global.php, o el parámetro (2) DIR_PAGE de (b) template/fr/page.php o (c)…
ModificadaAlta (7.5)7.3%💥 ExploitDetodas Restaurante Component FOR Joomla11/9/200716/6/2026
Vulnerabilidad de envío de archivo no restringido en el componente REstaurante (com_restaurante) para Joomla! permite a atacantes remotos enviar y ejecutar código PHP de su elección mediante una acción upload especificando un nombre de archivo con una extensión doble tal como .php.jpg, lo cual crea un archivo…
ModificadaAlta (7.5)1.2%💥 ExploitFirestorm Technologies Gmaps1/8/200716/6/2026
Vulnerabilidad de inyección SQL en index.php del componente para Joomla! Firestorm Technologies GMaps (com_gmaps) 1.00 permite a atacantes remotos ejecutar comandos sql de su elección mediante el parámetro mapId en la acción viewmap.
ModificadaAlta (7.5)2.4%💥 ExploitInforest Communications Supercali5/7/200716/6/2026
Vulnerabilidad de inyección SQL en index.php de SuperCali PHP Event Calendar 0.4.0 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro o.
ModificadaAlta (7.5)1.1%—Infinity Technologies Infinitytechs Restaurants CM4/12/200616/6/2026
Múltiples vulnerabilidades de inyección SQL en Infinitytechs Restaurants CM permiten a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro (1) id en el rating.asp, (2) mealid en el meal_rest.asp y (3)resid en el res_details.asp.
ModificadaMedia (4.3)3.4%💥 ExploitZyxel Prestige 660h-6131/7/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la secuencia Forms/rpSysAdmin del router ADSL Zyxel Prestige 660H-61 ejecutando el software empotrado (firmware) 3.40(PT.0)b32 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante valores codificados en…
ModificadaMedia (6.4)1.7%—Zyxel P2000w Version 1 Voip Wifi PhoneZyxel Prestige 2000w V.1voip Wi-fi Phone21/11/200516/6/2026
Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.
ModificadaMedia (6.4)1.2%—Zyxel Prestige 2000w V.1voip Wi-fi Phone21/11/200516/6/2026
Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or spoofing the hardcoded DNS servers. NOTE: it could be argued that this issue reflects an inherent limitation of DNS…
ModificadaMedia (5)1.7%—Zyxel Prestige 650r-3124/5/200516/6/2026
ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.
ModificadaMedia (5)1.2%—Netgear Rt311Netgear Rt314Zyxel Prestige2/5/200516/6/2026
Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.
ModificadaMedia (5)6.6%💥 ExploitZyxel PrestigeZyxel Zynos31/12/200416/6/2026
ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
ModificadaMedia (5)1.4%—Zyxel PrestigeZyxel Zynos13/9/200416/6/2026
Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (5)1.6%—Zyxel Prestige6/8/200416/6/2026
Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.
ModificadaAlta (10)2.2%—Veritas Bare Metal Restore31/12/200316/6/2026
Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.
ModificadaMedia (5)1.6%—Scaramanga Firestorm IDS31/12/200216/6/2026
Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.
ModificadaMedia (5)3.3%💥 ExploitZyxel Prestige4/10/200216/6/2026
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
ModificadaMedia (5)3.2%💥 ExploitZyxel Prestige4/10/200216/6/2026
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
ModificadaMedia (5)4.3%—Deep Forest Software Quik-serv Webserver3/7/200216/6/2026
Vulnerabilidad de atraviesamiento de directorios en Quik-Serv HTTP server 1.1B permite a atacantes remotos la lectura de ficheros arbitrarios mediante un .. (punto punto) en la URL.
ModificadaMedia (5)3.3%💥 ExploitZyxel Prestige 1600Zyxel Prestige 68114/12/200116/6/2026
Zyxel Prestige 681 y 1600 SDSL Routers permite a atacantes remotos causar una Denegación de Servicio (DoS) mediante la malformación de paquetes con:1: una longitud de IP menor que el tamaño real de los paquetes, 2: paquetes fragmentados cuyo tamaño excede los 64 kilobytes después haber sido reensamblados.
ModificadaAlta (7.5)1.5%—Zyxel Prestige14/8/200116/6/2026
ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.