Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

2279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.32%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.
ModificadaMedia (6.7)0.32%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.
ModificadaMedia (6.7)0.32%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.
ModificadaMedia (6.7)0.32%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
ModificadaMedia (6.7)0.32%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
ModificadaCrítica (9.8)0.93%—Tenda Ac10 Firmware8/6/202317/6/2026
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.
ModificadaAlta (8.8)1.2%—Tenda G103 Firmware6/6/20239/7/2026
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
ModificadaCrítica (9.8)1.2%—Tenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function.
ModificadaCrítica (9.8)1.1%—Tenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
ModificadaAlta (7.5)0.92%—Tenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
ModificadaCrítica (9.8)0.86%—Tenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
ModificadaCrítica (9.8)1.1%—Tenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.
ModificadaCrítica (9.8)2.1%💥 PoCTenda AC8 Firmware2/6/202317/6/2026
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.
ModificadaCrítica (9.8)0.95%—Tenda AC6 Firmware27/5/202317/6/2026
A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)2.0%—Tenda AC5 Firmware16/5/202317/6/2026
Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack
ModificadaAlta (8.8)9.7%—Tenda Ac23 Firmware11/5/202317/6/2026
A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.27%—Tenda CP3 Firmware10/5/202317/6/2026
Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware
ModificadaCrítica (9.8)0.45%—Tenda CP3 Firmware10/5/202317/6/2026
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
ModificadaCrítica (9.8)1.2%—Tenda CP3 Firmware10/5/202317/6/2026
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
ModificadaCrítica (9.8)0.66%—Tenda CP3 Firmware10/5/202317/6/2026
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
ModificadaAlta (7.5)0.24%—Tenda CP3 Firmware10/5/202317/6/2026
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.
ModificadaCrítica (9.8)2.4%—Tenda Ac18 Firmware5/5/202317/6/2026
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.