Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 1.1% | — | Netgear Ms90 FirmwareNetgear Rax20 FirmwareNetgear Rax200 FirmwareNetgear Rax35 Firmware+23 | 11/8/2026 | 9/9/2026 | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. | |
| Analizada | Media (4.3) | 0.27% | — | Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+22 | 11/8/2026 | 9/9/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |
| Analizada | Media (4.3) | 0.22% | — | Netgear Rax20 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 Firmware+9 | 11/8/2026 | 9/9/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. | |
| Analizada | Baja (1.9) | 0.51% | — | Netgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 Firmware+15 | 11/8/2026 | 9/9/2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | |
| Analizada | Baja (1.9) | 0.51% | — | Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+16 | 11/8/2026 | 9/9/2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | |
| Analizada | Baja (1.1) | 0.60% | — | Netgear Mr70 FirmwareNetgear Mr90 FirmwareNetgear Ms70 FirmwareNetgear Ms90 Firmware+11 | 11/8/2026 | 9/9/2026 | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. | |
| Analizada | Baja (1.1) | 0.51% | — | Netgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 FirmwareNetgear Rax42v2 Firmware+7 | 11/8/2026 | 9/9/2026 | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. | |
| Analizada | Alta (7) | 0.10% | — | Intel Xeon 6337p FirmwareIntel Xeon 6349p FirmwareIntel Xeon 6353p FirmwareIntel Xeon 6357p Firmware+69 | 11/8/2026 | 29/9/2026 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur… | |
| Analizada | Media (6.5) | 0.27% | — | HPE Integrated Lights-out 6 Firmware | 5/8/2026 | 10/8/2026 | A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. | |
| Aplazada | Crítica (9.3) | 0.79% | 💥 PoC | Zbtlink Router FirmwareAIOpenwrtAI | 5/8/2026 | 9/9/2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's… | |
| Analizada | Alta (7.1) | 0.76% | — | Tp-link Tapo P110 Firmware | 4/8/2026 | 7/8/2026 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may… | |
| Analizada | Alta (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analizada | Crítica (9.6) | 0.19% | — | Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+197 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | |
| Analizada | Alta (7.4) | 0.16% | — | Qualcomm Orne FirmwareQualcomm Palawan25 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+50 | 4/8/2026 | 6/8/2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qam8295p FirmwareQualcomm Qca6696 FirmwareQualcomm Sa8295p Firmware | 4/8/2026 | 6/8/2026 | Memory Corruption while processing IOCTL device driver requests with invalid arguments. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qam8295p FirmwareQualcomm Qca6574au FirmwareQualcomm Qca6595au FirmwareQualcomm Qca6678aq Firmware+32 | 4/8/2026 | 6/8/2026 | Memory Corruption when handling malformed request parameters in the fingerprint TA. | |
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Analizada | Media (6.7) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+48 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Lemans AU Lgit FirmwareQualcomm Lemansau FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+29 | 4/8/2026 | 6/8/2026 | Memory corruption while processing a packet with a size close to the maximum allowed value. | |
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAIUnknown Vendor Product FirmwareAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | |
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI | 4/8/2026 | 4/8/2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN… | |
| Pendiente de análisis | Baja (1.8) | 0.11% | — | Caliptra Core ROMAITaphome Core FirmwareAI | 4/8/2026 | 3/9/2026 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different… |