Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.43% | — | Clerk/astroClerk/backendClerk/chrome-extensionClerk/clerk-expo+13 | 11/5/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a… | |
| Pendiente de análisis | Alta (7.5) | 0.59% | 💥 PoC | Mikrotik RouterosAI | 8/5/2026 | 17/6/2026 | Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445. | |
| Analizada | Baja (2.1) | 0.39% | — | Router-for-me Cliproxyapi | 7/5/2026 | 17/6/2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack… | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | Mikrotik RouterosAIOpenvpnAIMikrotik CapsmanAI | 5/5/2026 | 7/10/2026 | RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate… | |
| Aplazada | Media (5.5) | 0.50% | — | Mikrotik RouterosAI | 2/5/2026 | 17/6/2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The… | |
| Pendiente de análisis | Alta (8.7) | 0.53% | — | Moxa Secure RouterAI | 27/4/2026 | 17/6/2026 | An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management interface, an unauthenticated remote attacker could send specially crafted requests that trigger a buffer overflow condition,… | |
| Pendiente de análisis | Media (6) | 0.35% | — | Moxa Secure RouterAI | 27/4/2026 | 17/6/2026 | An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful exploitation of this vulnerability could… | |
| Aplazada | Media (5.5) | 0.54% | — | Decolua 9routerAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | Sharp RoutersAI | 25/3/2026 | 17/6/2026 | SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over. | |
| Analizada | Alta (7.3) | 0.20% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later | |
| Analizada | Media (5.6) | 0.18% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to cause unexpected behavior. We have already fixed the vulnerability in the following version: QuRouter… | |
| Analizada | Media (4) | 0.20% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later | |
| Analizada | Baja (0.9) | 0.28% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the… | |
| Analizada | Alta (7.1) | 0.45% | — | Kube-router | 18/3/2026 | 17/6/2026 | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling… | |
| Analizada | Alta (7.5) | 0.32% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR. | |
| Analizada | Alta (7.2) | 0.22% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in the web interface of UBR. | |
| Analizada | Alta (8.8) | 0.49% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise. | |
| Analizada | Crítica (9.1) | 0.27% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server… | |
| Analizada | Crítica (9.1) | 0.41% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates. | |
| Analizada | Media (6.5) | 0.25% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files. | |
| Analizada | Media (6.2) | 0.08% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates. | |
| Analizada | Alta (7.8) | 0.17% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo. | |
| Analizada | Media (4.9) | 0.33% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an empty list does not enforce any restrictions and allows all network traffic to pass unfiltered. | |
| Analizada | Media (4.9) | 0.33% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these values are not supported and do not trigger any validation error. Instead, they are silently interpreted as network 0 which results in no networks being blocked at all. | |
| Analizada | Alta (8.8) | 0.56% | — | Mbs-solutions Universal Bacnet Router Firmware | 9/3/2026 | 17/6/2026 | A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise. |