Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.7% | — | Totolink Ex300 V2 Firmware | 30/3/2022 | 17/6/2026 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo. | |
| Modificada | Alta (7.5) | 5.0% | — | Asus Gt-ax11000 FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax56u Firmware+14 | 19/11/2021 | 9/7/2026 | An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS… | |
| Modificada | Crítica (9.8) | 6.5% | — | Asus Gt-ax11000 FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax56u Firmware+14 | 19/11/2021 | 9/7/2026 | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi… | |
| Modificada | Media (5.3) | 2.1% | 💥 PoC | Asus Gt-axe11000 FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax58u Firmware+1 | 12/11/2021 | 17/6/2026 | ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames. | |
| Modificada | Alta (7.5) | 1.3% | — | Altus Nexto Nx3003 FirmwareAltus Nexto Nx3004 FirmwareAltus Nexto Nx3005 FirmwareAltus Nexto Nx3010 Firmware+11 | 23/8/2021 | 17/6/2026 | Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110… | |
| Modificada | Alta (8.8) | 3.5% | — | Altus Nexto Nx3003 FirmwareAltus Nexto Nx3004 FirmwareAltus Nexto Nx3005 FirmwareAltus Nexto Nx3010 Firmware+11 | 23/8/2021 | 17/6/2026 | Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0,… | |
| Modificada | Media (6.5) | 0.53% | — | Altus Nexto Nx3003 FirmwareAltus Nexto Nx3004 FirmwareAltus Nexto Nx3005 FirmwareAltus Nexto Nx3010 Firmware+11 | 23/8/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto… | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767 | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276 | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet | |
| Modificada | Media (5.3) | 0.80% | — | NEC Aterm Wg2600hs FirmwareNEC Aterm Wx3000hp Firmware | 26/4/2021 | 17/6/2026 | Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall function. | |
| Modificada | Crítica (9.8) | 2.4% | — | Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+32 | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. | |
| Modificada | Alta (7.5) | 2.2% | — | Asus Zenwifi AX (xt8) FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax56u Firmware+23 | 12/4/2021 | 17/6/2026 | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a… | |
| Modificada | Alta (8.8) | 0.95% | — | Siemens Ruggedcom Rm1224 FirmwareSiemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance X300wg Firmware+11 | 15/3/2021 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions… | |
| Modificada | Alta (7.5) | 2.7% | — | Asus Rt-ax3000 Firmware | 5/2/2021 | 17/6/2026 | Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error. | |
| Modificada | Alta (7.2) | 8.5% | — | Cisco Ex60 FirmwareCisco Ex90 FirmwareCisco Sx10 FirmwareCisco Sx20 Firmware+17 | 23/9/2020 | 17/6/2026 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to… | |
| Modificada | Media (5.5) | 0.19% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure. | |
| Modificada | Media (6.3) | 0.28% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 7Microsoft Windows Server 2008Siemens Axiom Multix M FirmwareSiemens Axiom Vertix MD Trauma Firmware+63 | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | |
| Modificada | Media (4) | 0.23% | — | Samsung 840 EVO FirmwareSamsung 850 EVO FirmwareSamsung T3 FirmwareSamsung T5 Firmware+3 | 20/11/2018 | 17/6/2026 | An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with… | |
| Modificada | Alta (8.6) | 4.2% | — | Siemens Scalance X408 FirmwareSiemens Scalance X300 FirmwareSiemens Scalance X414 Firmware | 12/9/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will… | |
| Modificada | Media (6.1) | 1.0% | — | Siemens Scalance X300 FirmwareSiemens Scalance X-200 IRT FirmwareSiemens Scalance X-200 Firmware | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET… | |
| Modificada | Media (4.8) | 0.83% | — | Siemens Scalance X200irt FirmwareSiemens Scalance X300 FirmwareSiemens Scalance X200 Firmware | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to… | |
| Modificada | Alta (8.8) | 0.95% | — | Siemens Rfid 181-eip FirmwareSiemens Ruggedcom Wimax FirmwareSiemens Scalance X200 FirmwareSiemens Scalance X200irt Firmware+5 | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All… |