Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.38% | — | Archerirm Archer | 17/10/2023 | 17/6/2026 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data… | |
| Modificada | Media (6.5) | 0.46% | — | Archerirm Archer | 17/10/2023 | 17/6/2026 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release. | |
| Modificada | Alta (8) | 0.40% | — | Tp-link Archer Ax6000 Firmware | 6/9/2023 | 17/6/2026 | Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbitrary OS commands. | |
| Modificada | Alta (8) | 0.49% | — | Tp-link Archer Ax50 FirmwareTp-link Archer A10 FirmwareTp-link Archer Ax10 FirmwareTp-link Archer Ax11000 Firmware | 6/9/2023 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions… | |
| Modificada | Alta (8) | 0.40% | — | Tp-link Archer C5400 Firmware | 6/9/2023 | 17/6/2026 | Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands. | |
| Modificada | Alta (8) | 0.40% | — | Tp-link Archer C7 Firmware | 6/9/2023 | 17/6/2026 | Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided. | |
| Modificada | Alta (8) | 0.43% | — | Tp-link Archer C3150 Firmware | 6/9/2023 | 17/6/2026 | Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.49% | — | Tp-link Archer A10 Firmware | 6/9/2023 | 17/6/2026 | Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.55% | — | Tp-link Archer C1200 FirmwareTp-link Archer C9 Firmware | 6/9/2023 | 17/6/2026 | Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.41% | — | Tp-link Archer C20 Firmware | 6/9/2023 | 17/6/2026 | Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication. | |
| Modificada | Alta (8.8) | 0.40% | — | Tp-link Archer C55 FirmwareTp-link Archer C50 V3 Firmware | 6/9/2023 | 17/6/2026 | Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary OS command. | |
| Modificada | Alta (8) | 0.47% | — | Tp-link Archer C55 FirmwareTp-link Archer C50 V3 Firmware | 6/9/2023 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506', and Archer C20 firmware versions… | |
| Modificada | Crítica (9.8) | 0.70% | — | Tp-link Archer Ax21 Firmware | 1/8/2023 | 17/6/2026 | TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow. | |
| Modificada | Alta (7.5) | 1.4% | — | Tp-link Archer C2 V1 FirmwareTp-link Archer C20 FirmwareTp-link Archer C50 Firmware | 18/7/2023 | 9/7/2026 | TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data. | |
| Modificada | Media (5.5) | 0.19% | — | Archerirm Archer | 14/7/2023 | 17/6/2026 | An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files. | |
| Modificada | Media (5.4) | 0.51% | — | Archerirm Archer | 14/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script. | |
| Modificada | Alta (8) | 0.38% | — | Archerirm Archer | 14/7/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request. | |
| Modificada | Media (6.5) | 0.48% | — | Archerirm Archer | 14/7/2023 | 17/6/2026 | An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication. | |
| Modificada | Media (6.5) | 0.58% | — | Archerirm Archer | 14/7/2023 | 17/6/2026 | An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL. | |
| Modificada | Crítica (9.8) | 1.4% | — | Tp-link Archer Ax10 Firmware | 16/6/2023 | 9/7/2026 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | |
| Modificada | Media (6.7) | 1.8% | 💥 PoC | Tp-link Archer Vr1600v Firmware | 19/5/2023 | 17/6/2026 | A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level… | |
| Modificada | Media (6.5) | 0.32% | — | Tp-link Archer C7 Firmware | 11/5/2023 | 17/6/2026 | A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The… | |
| Modificada | Media (5.4) | 0.29% | — | Archerirm Archer | 1/5/2023 | 17/6/2026 | Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release. | |
| Modificada | Media (6.5) | 0.84% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `variable_name` and `variable_value` parameter value in the `sql/instance.py` `param_edit` endpoint is passed to a… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `db_name` in the `sql/data_dictionary.py` `table_list` endpoint is passed to the methods that follow in a given SQL… |