Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.86% | — | Gl-inet Gl-rm1AIGl-inet Gl-rm10AIGl-inet Gl-rm10rcAIGl-inet Gl-rm1peAI | 9/4/2026 | 17/6/2026 | A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The complexity of an attack is… | |
| Modificada | Alta (8.3) | 0.77% | — | Erlang/inetsErlang/otp | 7/4/2026 | 8/9/2026 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the… | |
| Analizada | Crítica (9.8) | 9.1% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlientems | 4/4/2026 | 24/7/2026 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Shinetheme TravelerAI | 18/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1. | |
| Analizada | Media (6.3) | 0.32% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to serve invalid client and CA certificates. The GL-RM1 will attempt to use the invalid certificates and… | |
| Analizada | Crítica (9.3) | 0.55% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. | |
| Analizada | Alta (7) | 0.34% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. | |
| Analizada | Alta (7) | 0.13% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification. | |
| Analizada | Media (4.7) | 0.27% | — | GNU Inetutils | 16/3/2026 | 17/6/2026 | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR. | |
| Analizada | Crítica (9.8) | 2.4% | 💥 Exploit | GNU Inetutils | 13/3/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | |
| Aplazada | Media (5.4) | 0.23% | — | Linethemes SmartfixAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4. | |
| Aplazada | Media (5.4) | 0.29% | — | Linethemes NanosoftAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2. | |
| Aplazada | Media (5.4) | 0.23% | — | Linethemes GLBAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes GLB glb allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GLB: from n/a through <= 1.2.2. | |
| Modificada | Alta (7) | 0.45% | — | Erlang/inetsErlang/otp | 13/3/2026 | 24/7/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. The server does not… | |
| Analizada | Crítica (9.8) | 3.6% | — | Gl-inet Ar300m16 Firmware | 12/3/2026 | 17/6/2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Crítica (9.8) | 3.6% | — | Gl-inet Ar300m16 Firmware | 12/3/2026 | 17/6/2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Alta (8.8) | 0.65% | — | Gl-inet Ar300m16 Firmware | 12/3/2026 | 17/6/2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 4.0% | — | Gl-inet Ar300m16 Firmware | 12/3/2026 | 17/6/2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbitrary commands via a… | |
| Modificada | Crítica (9.8) | 3.6% | — | Gl-inet Ar300m16 Firmware | 12/3/2026 | 17/6/2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Analizada | Media (6.6) | 0.70% | — | Fortinet Fortiweb | 10/3/2026 | 17/6/2026 | A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or… | |
| Analizada | Media (6.1) | 0.34% | — | Fortinet Fortisiem | 10/3/2026 | 17/6/2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering attack via spoofed URL parameters. | |
| Modificada | Alta (7.2) | 1.6% | — | Fortinet Fortisandbox Cloud | 10/3/2026 | 17/6/2026 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. | |
| Analizada | Media (6.5) | 0.60% | — | Fortinet Fortideceptor | 10/3/2026 | 17/6/2026 | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all… | |
| Analizada | Media (6.5) | 0.40% | — | Fortinet Fortiweb | 10/3/2026 | 17/6/2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests. | |
| Analizada | Media (6.6) | 0.66% | — | Fortinet Fortiweb | 10/3/2026 | 17/6/2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute… |