Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.57%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
ModificadaMedia (5.3)0.58%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
ModificadaMedia (5.3)0.56%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
ModificadaAlta (7.5)1.1%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
ModificadaAlta (7.5)0.74%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
ModificadaMedia (6.1)0.71%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
ModificadaMedia (5.3)0.76%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
ModificadaMedia (5.3)0.79%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
ModificadaMedia (5.3)0.78%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
ModificadaMedia (5.3)0.95%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.
ModificadaCrítica (9.8)0.89%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
ModificadaCrítica (9.8)0.89%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
ModificadaMedia (5.3)0.57%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
ModificadaMedia (5.3)0.85%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
ModificadaMedia (5.3)0.85%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
ModificadaAlta (7.5)0.96%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
ModificadaMedia (5.3)0.53%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
ModificadaMedia (5.3)0.57%—Zyxel Cloudcnm Secumanager29/9/202217/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
ModificadaMedia (5.9)0.38%—Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+620/9/202217/6/2026
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in…
ModificadaCrítica (9.8)1.7%—Zyxel Nas326 Firmware6/9/202217/6/2026
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
ModificadaAlta (7.8)1.1%💥 ExploitZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+2119/7/202217/6/2026
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions…
ModificadaMedia (6.5)1.4%—Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+2119/7/202217/6/2026
A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX…
ModificadaMedia (6.2)0.23%—Zyxel Gs1200-5 FirmwareZyxel Gs1200-5hp FirmwareZyxel Gs1200-8 FirmwareZyxel Gs1200-8hp Firmware9/6/202217/6/2026
An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.
ModificadaAlta (7.8)4.8%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00…
ModificadaAlta (7.8)6.2%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions…