Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.32% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet. | |
| Modificada | Media (6.7) | 0.32% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName. | |
| Modificada | Media (6.7) | 0.32% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList. | |
| Modificada | Media (6.7) | 0.32% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet. | |
| Modificada | Media (6.7) | 0.32% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda Ac10 Firmware | 8/6/2023 | 17/6/2026 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo. | |
| Modificada | Alta (8.8) | 1.2% | — | Tenda G103 Firmware | 6/6/2023 | 9/7/2026 | There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges. | |
| Modificada | Crítica (9.8) | 1.2% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function. | |
| Modificada | Alta (7.5) | 0.92% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. | |
| Modificada | Crítica (9.8) | 0.86% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 PoC | Tenda AC8 Firmware | 2/6/2023 | 17/6/2026 | Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function. | |
| Modificada | Crítica (9.8) | 0.95% | — | Tenda AC6 Firmware | 27/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 2.0% | — | Tenda AC5 Firmware | 16/5/2023 | 17/6/2026 | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack | |
| Modificada | Alta (8.8) | 9.7% | — | Tenda Ac23 Firmware | 11/5/2023 | 17/6/2026 | A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.27% | — | Tenda CP3 Firmware | 10/5/2023 | 17/6/2026 | Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware | |
| Modificada | Crítica (9.8) | 0.45% | — | Tenda CP3 Firmware | 10/5/2023 | 17/6/2026 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access. | |
| Modificada | Crítica (9.8) | 1.2% | — | Tenda CP3 Firmware | 10/5/2023 | 17/6/2026 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document. | |
| Modificada | Crítica (9.8) | 0.66% | — | Tenda CP3 Firmware | 10/5/2023 | 17/6/2026 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed. | |
| Modificada | Alta (7.5) | 0.24% | — | Tenda CP3 Firmware | 10/5/2023 | 17/6/2026 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials. | |
| Modificada | Crítica (9.8) | 2.4% | — | Tenda Ac18 Firmware | 5/5/2023 | 17/6/2026 | Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function. |