Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.56%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.
AnalizadaAlta (8.1)0.34%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
AnalizadaMedia (6.5)0.52%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a parameter specifying the log file to open (e.g., /tmp/weblog{some_number}), but this parameter is not properly validated, allowing an attacker to modify it to reference any…
AnalizadaMedia (6.5)0.35%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system.
AplazadaCrítica (9.2)0.29%—Zigbee CoordinatorAIZigbee RouterAI30/1/202617/6/2026
After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommissioning is required to…
AplazadaCrítica (9.3)1.6%—Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI27/1/202617/6/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue…
AplazadaCrítica (9.9)14%—Zoom Node Multimedia RoutersAI20/1/202617/6/2026
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.
AnalizadaMedia (5.4)0.27%—Eachitaly Wireless Mini Router Wireless-n 300m Firmware15/1/202617/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm.
AnalizadaMedia (6.5)0.19%—Shopify React-routerShopify Remix-run/react10/1/202617/6/2026
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server…
ModificadaMedia (6.1)0.87%—Shopify Remix-run/reactShopify React-router10/1/202610/9/2026
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended…
ModificadaAlta (8.2)0.53%—Shopify React-routerShopify Remix-run/react10/1/202615/7/2026
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript…
AnalizadaMedia (6.5)0.49%—Shopify React-router10/1/202617/6/2026
React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you…
ModificadaCrítica (9.1)17%💥 PoCShopify React-router/nodeShopify Remix-run/denoShopify Remix-run/node10/1/202615/7/2026
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it…
ModificadaAlta (7.6)0.50%💥 PoCShopify React-routerShopify Remix-run/react10/1/202615/7/2026
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if…
AplazadaAlta (8.8)0.46%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session…
AplazadaAlta (8.8)0.38%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this…
AnalizadaAlta (8.7)0.73%—Gargoyle-router Gargoyle31/12/202523/9/2026
Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shell commands on the…
AplazadaAlta (8.7)0.29%—ZBL Epon ONU Broadband RouterAIZBL V100r001AI31/12/202517/6/2026
ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuration endpoints. Attackers can exploit the vulnerability by accessing the configuration backup or password page to disclose the super user…
AplazadaAlta (8.7)0.30%—Nucom 11N Wireless RouterAI31/12/202517/6/2026
NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode…
AplazadaMedia (6.4)0.22%—LS Google MAP RouterAI12/12/202530/9/2026
The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
ModificadaCrítica (9.8)0.64%—Openmptcprouter9/12/20255/7/2026
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.
AnalizadaAlta (7.2)0.64%—Synology Router Manager4/12/202525/9/2026
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
AnalizadaMedia (4.3)0.43%—Synology Router Manager4/12/202525/9/2026
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
Orbitaley — Vulnerabilidades