Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.62%—Cisco Firepower Management Center 2600 FirmwareCisco Firepower Appliance 7030 FirmwareCisco Firepower Appliance 7110 FirmwareCisco Firepower Appliance 7115 Firmware+3016/10/201917/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of…
ModificadaMedia (4.8)0.80%—Cisco Firepower Management Center 2600 FirmwareCisco Firepower Appliance 7030 FirmwareCisco Firepower Appliance 7110 FirmwareCisco Firepower Appliance 7115 Firmware+3016/10/201917/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of…
ModificadaCrítica (9.8)1.5%—Netgear Mbr1515 FirmwareNetgear Mbr1516 FirmwareNetgear Dgn2200 FirmwareNetgear Dgn2200m Firmware+69/10/201917/6/2026
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
ModificadaCrítica (9.8)1.8%—Arlo Vmb3010 FirmwareArlo Vmb4000 FirmwareArlo Vmb3500 FirmwareArlo Vmb4500 Firmware+19/7/201917/6/2026
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
ModificadaCrítica (9.8)1.2%—Arlo Vmb3010 FirmwareArlo Vmb4000 FirmwareArlo Vmb3500 FirmwareArlo Vmb4500 Firmware+19/7/201917/6/2026
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
ModificadaAlta (8.8)8.5%💥 PoCTp-link Tl-wdr5620 FirmwareTp-link Tl-wdr3500 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+118/1/201917/6/2026
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
ModificadaAlta (8.8)0.94%—Cisco Secure Firewall Management CenterCisco Firepower Appliance 8360 FirmwareCisco Firepower Management Center 2500 FirmwareCisco Firepower Appliance 8120 Firmware+2821/6/201817/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the…
ModificadaMedia (5.3)0.81%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…
ModificadaMedia (5.3)1.3%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM…
ModificadaMedia (6.5)1.6%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force…
ModificadaMedia (6.5)1.4%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account…
ModificadaAlta (7.6)1.2%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a…
ModificadaMedia (5.4)0.96%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
ModificadaAlta (7.5)2.2%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566.
ModificadaAlta (8.8)0.91%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…
ModificadaAlta (7.5)2.5%—IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+417/5/201817/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473.
ModificadaAlta (7.8)1.8%—HP T790 FirmwareHP T795 FirmwareHP T1300 FirmwareHP T2300 Firmware+1823/1/201817/6/2026
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache StrutsIBM Storwize V3500 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V7000 Firmware+511/3/201717/6/2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP…
AnalizadaAlta (7.5)84%⚠ Explotación activa💥 ExploitTp-link Tl-wr741nd FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Archer C5 Firmware+722/4/201517/6/2026
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with…
ModificadaAlta (7.5)4.0%💥 PoCLinksys Ea3500 FirmwareLinksys Ea3500Linksys Ea6700 FirmwareLinksys Ea6700+161/11/201417/6/2026
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain…
ModificadaBaja (3.3)1.2%—Linksys Ea4500 FirmwareLinksys Ea4500Linksys Ea6500 FirmwareLinksys Ea6500+161/11/201417/6/2026
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…