Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.30%—Netgear Rbr50 FirmwareNetgear Rbk50 FirmwareNetgear Rbs50 Firmware15/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
ModificadaMedia (4.3)0.30%—Netgear Rbr50 FirmwareNetgear Rbk50 FirmwareNetgear Rbs50 Firmware15/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
ModificadaMedia (4.8)0.56%—Netgear Rbr50 FirmwareNetgear Rbk50 FirmwareNetgear Rbs50 Firmware15/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
ModificadaMedia (4.8)0.44%—Netgear Rbr20 FirmwareNetgear Rbs20 FirmwareNetgear Rbk20 FirmwareNetgear Rbr40 Firmware+515/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
ModificadaMedia (4.8)0.44%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+1315/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before…
ModificadaMedia (4.8)0.56%—Netgear Rbr50 FirmwareNetgear Rbs50 FirmwareNetgear Rbk50 Firmware15/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
ModificadaMedia (4.8)0.48%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+715/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before…
ModificadaMedia (4.8)0.44%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+715/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before…
ModificadaMedia (4.8)0.44%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+715/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before…
ModificadaMedia (4.8)0.44%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+715/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before…
ModificadaMedia (4.8)0.56%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+1315/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before…
ModificadaMedia (4.8)0.51%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+1215/4/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before…
ModificadaMedia (4.8)0.51%—Netgear D7800 FirmwareNetgear R7500 FirmwareNetgear R7800 FirmwareNetgear R8900 Firmware+1315/4/202017/6/2026
Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before…
ModificadaMedia (6.8)0.81%—Keeper K5 Firmware19/9/201917/6/2026
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
ModificadaMedia (6.8)0.34%—Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+14419/8/201917/6/2026
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
ModificadaMedia (6.3)0.34%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+237/8/201717/6/2026
A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled…
ModificadaMedia (6)0.26%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+267/8/201717/6/2026
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is…
ModificadaAlta (8.8)12%💥 ExploitZyxel Pk5001z Firmware25/7/201717/6/2026
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).
ModificadaAlta (7.5)37%💥 ExploitHak5 Wi-fi Pineapple Firmware31/3/201717/6/2026
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
ModificadaMedia (4.3)1.7%—K5N Webcalendar8/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.
ModificadaMedia (5)1.2%—K5N Webcalendar24/9/201116/6/2026
WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files.
ModificadaMedia (6.8)0.57%—K5N Webcalendar15/2/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (6.8)0.59%—K5N Webcalendar12/2/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors. NOTE: some of these details are…
ModificadaMedia (4.3)1.1%—K5N Webcalendar12/2/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained…
ModificadaAlta (7.8)1.7%—Sony Ericsson K530iSony Ericsson K610iSony Ericsson K618iSony Ericsson K660i+53/2/200916/6/2026
The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.