Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.81% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a DOM-based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is… | |
| Modificada | Alta (8.1) | 1.2% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to overwrite configuration information by injecting arbitrarily large payload. | |
| Modificada | Alta (7.1) | 0.62% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface. | |
| Modificada | Media (6.1) | 1.0% | — | Dell Idrac9 Firmware | 16/12/2020 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially… | |
| Modificada | Media (6.5) | 1.8% | — | Dell Idrac9 Firmware | 9/7/2020 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files. | |
| Modificada | Crítica (9.8) | 2.6% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the… | |
| Modificada | Crítica (9.8) | 3.3% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/setcfm… | |
| Modificada | Crítica (9.8) | 2.6% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Tendacn AC6 FirmwareTendacn AC9 FirmwareTendacn Ac15 FirmwareTendacn Ac18 Firmware | 22/5/2020 | 17/6/2026 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the… | |
| Modificada | Crítica (9.8) | 3.8% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 31/3/2020 | 17/6/2026 | Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data. | |
| Modificada | Media (4.3) | 0.88% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 7/11/2019 | 17/6/2026 | Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as… | |
| Modificada | Crítica (9.8) | 3.3% | — | Dell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted input data to the WS-MAN interface. | |
| Modificada | Crítica (9.8) | 3.3% | — | Dell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface. | |
| Modificada | Crítica (9.8) | 4.2% | — | Dell Idrac6 FirmwareDell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or… | |
| Modificada | Alta (7.5) | 1.4% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 Firmware | 25/4/2019 | 17/6/2026 | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list… | |
| Modificada | Alta (7.5) | 1.4% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 Firmware | 25/4/2019 | 17/6/2026 | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page… | |
| Modificada | Alta (8.8) | 0.94% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 13/12/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to… | |
| Analizada | Crítica (9.8) | 8.5% | ⚠ Explotación activa | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 Firmware | 30/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted… | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 FirmwareTenda Ac15 Firmware+1 | 29/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is… | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 FirmwareTenda Ac15 Firmware+1 | 29/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is… | |
| Modificada | Alta (7.5) | 1.1% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 FirmwareTenda Ac15 Firmware+1 | 29/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request,… | |
| Modificada | Crítica (9.8) | 1.3% | — | Tenda AC7 FirmwareTenda AC9 FirmwareTenda Ac10 FirmwareTenda Ac15 Firmware+1 | 29/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the… | |
| Modificada | Crítica (9.8) | 3.0% | — | Tenda AC9 FirmwareTenda Ac15 FirmwareTenda Ac18 Firmware | 29/10/2018 | 17/6/2026 | An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request. |