Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 3.2% | — | Tp-link Archer C4500xAI | 27/5/2024 | 17/6/2026 | The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue… | |
| Analizada | Media (5.3) | 0.44% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting when X-Forwarded-For header is enabled. | |
| Modificada | Alta (8.8) | 0.39% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release. | |
| Analizada | Media (5.4) | 0.51% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the… | |
| Analizada | Media (5.4) | 0.42% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a fixed release. | |
| Modificada | Media (5.4) | 0.46% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the… | |
| Analizada | Media (4.3) | 0.41% | — | Archerirm Archer | 6/5/2024 | 17/6/2026 | Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (6.8) | 0.58% | — | Tp-link Archer A54 Firmware | 3/5/2024 | 17/6/2026 | TP-Link Archer A54 libcmm.so dm_fillObjByStr Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A54 routers. Authentication is required to exploit this vulnerability. The specific… | |
| Analizada | Alta (8.1) | 1.2% | — | Tp-link Archer Ax21 Firmware | 3/5/2024 | 17/6/2026 | TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hotplugd daemon.… | |
| Analizada | Alta (8.8) | 0.71% | — | Tp-link Archer Ax21 Firmware | 3/5/2024 | 17/6/2026 | TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Media (6.8) | 0.74% | — | Tp-link Archer Ax21 Firmware | 3/5/2024 | 17/6/2026 | TP-Link Archer AX21 tmpServer Command 0x422 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentication is required to exploit this vulnerability. The specific… | |
| Analizada | Alta (8.8) | 0.72% | — | Tp-link Archer Ax21 Firmware | 3/5/2024 | 17/6/2026 | TP-Link Archer AX21 tdpServer Logging Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Tp-link Ex20v Ax1800AITp-link Archer C5V Ac1200AITp-link Td-w9970AITp-link Td-w9970v3AI+2 | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command Injection. This issue affects TP-Link EX20v… | |
| Analizada | Media (5.4) | 0.51% | — | Archerirm Archer | 8/3/2024 | 17/6/2026 | Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through… | |
| Modificada | Alta (7.5) | 0.50% | — | Archerirm Archer | 8/3/2024 | 17/6/2026 | Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via an internal URL. | |
| Analizada | Media (6.1) | 1.0% | — | Tp-link Archer Ax50 Firmware | 5/3/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an… | |
| Analizada | Media (5.7) | 0.52% | — | Archerirm Archer | 21/2/2024 | 17/6/2026 | Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the… | |
| Analizada | Media (4.3) | 0.39% | — | Archerirm Archer | 21/2/2024 | 17/6/2026 | Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with extra privileges. | |
| Modificada | Alta (8.8) | 1.1% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+1 | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi. | |
| Modificada | Alta (8) | 0.45% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Archer Axe75 Firmware | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.53% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings. | |
| Modificada | Media (5.4) | 0.46% | — | Archerirm Archer | 12/12/2023 | 17/6/2026 | Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the… | |
| Modificada | Alta (8.8) | 0.48% | — | Archerirm Archer | 12/12/2023 | 17/6/2026 | Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks,… | |
| Modificada | Alta (7.5) | 0.37% | — | Archerydms Archery | 16/11/2023 | 17/6/2026 | Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. |