Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.38%—Archerirm Archer17/10/202317/6/2026
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data…
ModificadaMedia (6.5)0.46%—Archerirm Archer17/10/202317/6/2026
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.
ModificadaAlta (8)0.40%—Tp-link Archer Ax6000 Firmware6/9/202317/6/2026
Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
ModificadaAlta (8)0.49%—Tp-link Archer Ax50 FirmwareTp-link Archer A10 FirmwareTp-link Archer Ax10 FirmwareTp-link Archer Ax11000 Firmware6/9/202317/6/2026
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions…
ModificadaAlta (8)0.40%—Tp-link Archer C5400 Firmware6/9/202317/6/2026
Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
ModificadaAlta (8)0.40%—Tp-link Archer C7 Firmware6/9/202317/6/2026
Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.
ModificadaAlta (8)0.43%—Tp-link Archer C3150 Firmware6/9/202317/6/2026
Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
ModificadaAlta (8.8)0.49%—Tp-link Archer A10 Firmware6/9/202317/6/2026
Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands.
ModificadaAlta (8.8)0.55%—Tp-link Archer C1200 FirmwareTp-link Archer C9 Firmware6/9/202317/6/2026
Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands.
ModificadaAlta (8.8)0.41%—Tp-link Archer C20 Firmware6/9/202317/6/2026
Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.
ModificadaAlta (8.8)0.40%—Tp-link Archer C55 FirmwareTp-link Archer C50 V3 Firmware6/9/202317/6/2026
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary OS command.
ModificadaAlta (8)0.47%—Tp-link Archer C55 FirmwareTp-link Archer C50 V3 Firmware6/9/202317/6/2026
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506', and Archer C20 firmware versions…
ModificadaCrítica (9.8)0.70%—Tp-link Archer Ax21 Firmware1/8/202317/6/2026
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.
ModificadaAlta (7.5)1.4%—Tp-link Archer C2 V1 FirmwareTp-link Archer C20 FirmwareTp-link Archer C50 Firmware18/7/20239/7/2026
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
ModificadaMedia (5.5)0.19%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
ModificadaMedia (5.4)0.51%—Archerirm Archer14/7/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
ModificadaAlta (8)0.38%—Archerirm Archer14/7/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
ModificadaMedia (6.5)0.48%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
ModificadaMedia (6.5)0.58%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
ModificadaCrítica (9.8)1.4%—Tp-link Archer Ax10 Firmware16/6/20239/7/2026
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
ModificadaMedia (6.7)1.8%💥 PoCTp-link Archer Vr1600v Firmware19/5/202317/6/2026
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level…
ModificadaMedia (6.5)0.32%—Tp-link Archer C7 Firmware11/5/202317/6/2026
A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The…
ModificadaMedia (5.4)0.29%—Archerirm Archer1/5/202317/6/2026
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release.
ModificadaMedia (6.5)0.84%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `variable_name` and `variable_value` parameter value in the `sql/instance.py` `param_edit` endpoint is passed to a…
ModificadaMedia (6.5)0.83%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `db_name` in the `sql/data_dictionary.py` `table_list` endpoint is passed to the methods that follow in a given SQL…
Orbitaley — Vulnerabilidades