Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Netgear Fvs3186/12/200416/6/2026
La administración basada en web de Netgear FVS318 VPN Router permite a atacantes remotos causar una denegación de servicio (impide conexiones nuevas) mediante un gran número de conexiones HTTP abiertas.
ModificadaAlta (7.5)2.7%💥 ExploitNetgear Rp11424/5/200416/6/2026
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.
ModificadaMedia (6.4)2.8%💥 ExploitNetgear Fm114p31/12/200316/6/2026
Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.
ModificadaAlta (7.8)1.8%—Netgear Fm114p31/12/200216/6/2026
Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.
ModificadaAlta (7.5)1.5%—Netgear Rp11431/12/200216/6/2026
Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed.
ModificadaAlta (7.1)1.1%—Netgear Fm114p31/12/200216/6/2026
Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other information in cleartext, which could allow local users to obtain sensitive information.
ModificadaAlta (7.5)1.6%—Netgear Fm114p31/12/200216/6/2026
NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.
ModificadaMedia (5)1.8%—Netgear Rm356Netgear Rt33831/12/200216/6/2026
Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.
ModificadaBaja (2.1)0.63%—Netgear Fvs31831/12/200216/6/2026
NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information.
ModificadaAlta (7.5)1.6%—Netgear Rt31429/5/200216/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en la interfaz de administración de web para el router NetGear RT314 y RT311 permite a atacantes remotos que ejecuten un script arbitrario en otro cliente por medio de una URL que contiene el script.
ModificadaMedia (5)1.3%—Netgear Rp11425/3/200216/6/2026
Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26, cuando es configurado para bloquear el tráfico bajo el puerto 1024, permite atacantes remotos causar una negación de servicio (cuelgue) vía una exploración de puerto del puerto WAN
ModificadaMedia (5)2.4%—Atmel FirmwareLinksys Wap11Netgear Me10221/12/200116/6/2026
El Wireless Acces Point (WAP) Atmel Firmware 1.3 permite a atacantes remotos causar una denegación de servicio mediante una petición SNMP con una cadena de comunidad distinta de "public", oun OID (identificador de objeto) desconocido lo que hace que el WAP deniege peticiones SNMP subsiguientes.
ModificadaAlta (7.5)1.6%—Atmel 802.11b Vnet-b Access PointLinksys Wap11Netgear Me10221/7/20019/10/2026
SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.