Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1248 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.38%—Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+214/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects the function bs_GetManPwd in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to information…
AplazadaMedia (5.5)0.38%—Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+214/7/202517/6/2026
A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This vulnerability affects the function bs_GetHostInfo in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to information disclosure.…
AnalizadaMedia (5.5)0.70%—Lb-link Bl-ac3600 Firmware14/7/202517/6/2026
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi-bin/lighttpd.cgi of the component Web Management Interface. The manipulation of the argument Password leads to information disclosure. It is possible to initiate the…
AnalizadaAlta (7.1)0.25%—Lb-link Bl-ac3600 Firmware14/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required to approach this attack. The exploit has…
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption while processing video packets received from video firmware.
AnalizadaCrítica (9.1)0.31%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1048/7/202517/6/2026
Cryptographic issue occurs due to use of insecure connection method while downloading.
AnalizadaAlta (8.5)0.42%—Msp360 Backup22/5/202517/6/2026
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).
AplazadaMedia (5.3)0.26%—Embed360 Embed AND Integrate Etsy ShopAI19/5/202517/6/2026
Missing Authorization vulnerability in Embed360 Embed and Integrate Etsy Shop embed-and-integrate-etsy-shop allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Embed and Integrate Etsy Shop: from n/a through <= 1.0.8.
AnalizadaMedia (6.1)0.35%—Yofla 360 Product Rotation15/5/202517/6/2026
The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.
AplazadaMedia (5.9)0.22%—Bistromatic N360 Splash ScreenAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen n360-splash-screen allows Stored XSS.This issue affects N360 | Splash Screen: from n/a through <= 1.0.6.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2626/5/202517/6/2026
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
AplazadaMedia (5.3)0.46%—Wangshen Secgate 3600AI2/5/202517/6/2026
A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown function of the file /?g=route_ispinfo_export_save. The manipulation of the argument file_name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (5.3)12%—Wangshen Secgate 3600AI2/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some unknown processing of the file ?g=obj_area_export_save. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (8.5)0.44%—Msp360 Backup1/5/202517/6/2026
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
AplazadaMedia (5.3)1.1%💥 ExploitWangshen Secgate 3600 2400AI29/4/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the…
AplazadaMedia (5.3)20%—Lb-link Bl-ac3600AI29/4/202517/6/2026
A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the component Password Handler. The manipulation of the argument routepwd leads to command injection. It is possible to initiate the…
AplazadaAlta (8.6)0.40%—Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+1926/4/202517/6/2026
A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl,…
AplazadaMedia (5.1)0.22%—Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+1926/4/202517/6/2026
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000…
AplazadaMedia (6.9)0.36%—Gl-inet GL A1300 Slate PlusAIGl-inet GL Ar300m16 ShadowAIGl-inet GL Ar300m ShadowAIGl-inet GL Ar750 CretaAI+1926/4/202517/6/2026
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000…
AplazadaMedia (6.5)0.26%—Andrey Mikhalchuk 360 ViewAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrey Mikhalchuk 360 View 360-view allows Stored XSS.This issue affects 360 View: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.29%—Ione360 ConfiguratorAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iONE360 iONE360 configurator ione360-configurator allows Reflected XSS.This issue affects iONE360 configurator: from n/a through <= 2.0.57.
AplazadaAlta (7.1)0.19%—Sitesearch360 Site Search 360AI16/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 site-search-360 allows Stored XSS.This issue affects Site Search 360: from n/a through <= 2.1.8.
AnalizadaAlta (7.5)0.26%—Qualcomm Qcn9070 FirmwareQualcomm Qcn9072 FirmwareQualcomm Qcn9074 FirmwareQualcomm Qcn9100 Firmware+2657/4/202517/6/2026
Transient DOS may occur while parsing SSID in action frames.
AnalizadaAlta (7.5)0.26%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+2217/4/202517/6/2026
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.