Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Tendacn G1 FirmwareTendacn G3 Firmware | 4/2/2022 | 17/6/2026 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tendacn G1 FirmwareTendacn G3 Firmware | 4/2/2022 | 17/6/2026 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Inim Smartliving 505 FirmwareInim Smartliving 515 FirmwareInim Smartliving 1050 FirmwareInim Smartliving 1050g3 Firmware+2 | 29/4/2021 | 17/6/2026 | An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is… | |
| Modificada | Crítica (9.8) | 2.0% | — | Inim Smartliving 505 FirmwareInim Smartliving 515 FirmwareInim Smartliving 1050 FirmwareInim Smartliving 1050g3 Firmware+2 | 29/4/2021 | 17/6/2026 | Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system. | |
| Modificada | Alta (8.8) | 5.2% | — | Inim Smartliving 505 FirmwareInim Smartliving 515 FirmwareInim Smartliving 1050 FirmwareInim Smartliving 1050g3 Firmware+2 | 29/4/2021 | 17/6/2026 | Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.cgi binary. The vulnerable CGI binary (ELF 32-bit LSB executable, ARM) is… | |
| Modificada | Crítica (9.8) | 3.2% | — | Tendacn G1 FirmwareTendacn G3 Firmware | 16/4/2021 | 17/6/2026 | Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function… | |
| Modificada | Crítica (9.8) | 25% | — | Tendacn G0 FirmwareTendacn G1 FirmwareTendacn G3 Firmware | 16/4/2021 | 17/6/2026 | Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs… | |
| Modificada | Crítica (9.8) | 2.8% | — | Tenda G1 FirmwareTenda G3 Firmware | 14/4/2021 | 17/6/2026 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit. | |
| Modificada | Crítica (9.8) | 2.8% | — | Tenda G1 FirmwareTenda G3 Firmware | 14/4/2021 | 17/6/2026 | Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit. | |
| Modificada | Crítica (9.8) | 2.9% | — | Tenda G1 FirmwareTenda G3 Firmware | 14/4/2021 | 17/6/2026 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function directly passes the parameter "qosIndex" to strcpy without limit. | |
| Modificada | Media (6.7) | 0.46% | — | HP Elite X2 1012 G1 FirmwareHP Elite X2 1012 G2 FirmwareHP Elitebook 1030 G1 FirmwareHP Elitebook 1040 G4 Firmware+10 | 12/8/2020 | 17/6/2026 | The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file. | |
| Modificada | Media (6) | 0.55% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+129 | 22/7/2020 | 17/6/2026 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table. | |
| Modificada | Alta (7.5) | 1.7% | — | Wavlink Wl-wn575a3 FirmwareWavlink Wl-wn579g3 FirmwareWavlink Wn531a6 FirmwareWavlink Wn535g3 Firmware+9 | 7/5/2020 | 17/6/2026 | An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4,… | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Wavlink Wn530hg4 FirmwareWavlink Wn531g3 FirmwareWavlink Wn533a8 FirmwareWavlink Wn551k1 Firmware | 7/5/2020 | 17/6/2026 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a… | |
| Modificada | Alta (7.5) | 1.8% | — | Wavlink Wn530hg4 FirmwareWavlink Wn531g3 FirmwareWavlink Wn572hg3 Firmware | 7/5/2020 | 17/6/2026 | An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). Affected Devices: Wavlink WN530HG4, Wavlink WN531G3, and Wavlink… | |
| Modificada | Alta (8.8) | 2.7% | — | Wavlink Wl-wn575a3 FirmwareWavlink Wl-wn530hg4 FirmwareWavlink Wl-wn579g3 Firmware | 7/5/2020 | 17/6/2026 | An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the same time. The POST request itself is not validated to ensure it came from the active session. Affected devices are:… | |
| Modificada | Alta (7.5) | 1.8% | — | Wavlink Wl-wn579g3 FirmwareWavlink Wl-wn575a3 FirmwareWavlink Wl-wn530hg4 FirmwareWavlink Wn531g3 Firmware+11 | 27/4/2020 | 17/6/2026 | An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any… | |
| Modificada | Crítica (9.8) | 1.3% | — | Tonnet Tat-77104g1 FirmwareTonnet Tat-70432n FirmwareTonnet Tat-71416g1 FirmwareTonnet Tat-71832g1 Firmware+4 | 27/2/2020 | 17/6/2026 | DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tonnet Tat-77104g1 FirmwareTonnet Tat-70432n FirmwareTonnet Tat-71416g1 FirmwareTonnet Tat-71832g1 Firmware+4 | 27/2/2020 | 17/6/2026 | DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the default password and gain access to the system. | |
| Modificada | Media (5.5) | 0.29% | — | Waltonbd Primo G3 Firmware | 14/11/2019 | 17/6/2026 | The Walton Primo G3 Android device with a build fingerprint of WALTON/Primo_GM3/Primo_GM3:8.1.0/O11019/1522737198:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Alta (7.2) | 2.0% | — | HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+98 | 5/11/2019 | 17/6/2026 | A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management… | |
| Modificada | Media (5.9) | 1.0% | — | Chuango H4 Plus FirmwareChuango AWV Plus FirmwareChuango G5W 3G FirmwareChuango G5 Plus Firmware+6 | 8/5/2019 | 17/6/2026 | The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as… | |
| Modificada | Media (4.6) | 1.1% | 💥 PoC | HP 240 G1 FirmwareHP 245 G1 FirmwareHP 1000-1300 FirmwareHP 250 G1 Notebook PC Firmware+30 | 3/10/2018 | 17/6/2026 | A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014. | |
| Modificada | Alta (9) | 2.8% | — | HP Storageworks Modular Smart Array P2000 G3 Firmware | 17/12/2010 | 16/6/2026 | HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges. |