Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3090▲ 500 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

26.338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)2.6%—IWT Facesentry Access Control System Firmware24/12/202517/6/2026
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
AnalizadaMedia (5.1)0.24%—IWT Facesentry Access Control System Firmware24/12/202517/6/2026
FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated…
ModificadaCrítica (9.8)0.73%—IWT Facesentry Access Control System Firmware24/12/202517/6/2026
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
ModificadaMedia (5.1)0.20%—Teradek Cube Firmware24/12/202517/6/2026
Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration interface.
ModificadaMedia (5.1)0.20%—Teradek Slice Firmware24/12/202517/6/2026
Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visits the page.
ModificadaMedia (5.1)0.22%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a…
AnalizadaAlta (8.7)0.78%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting…
AnalizadaCrítica (9.3)0.39%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.
ModificadaAlta (7.1)0.49%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring…
AnalizadaAlta (7.1)0.47%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and…
ModificadaAlta (8.7)0.48%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system…
AnalizadaAlta (8.7)0.60%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
AnalizadaAlta (8.7)0.53%—Flir AX8 Firmware24/12/202517/6/2026
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
ModificadaCrítica (9.3)0.62%—Flir AX8 Firmware24/12/202517/6/2026
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.
ModificadaMedia (5.5)12%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed…
ModificadaAlta (8.9)1.2%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request Handler. This manipulation of the argument page causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and…
AnalizadaAlta (8.9)1.1%—Tenda Wh450 Firmware23/12/202517/6/2026
A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaCrítica (9.8)1.3%—Linksys E5600 Firmware23/12/202517/6/2026
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
AnalizadaCrítica (9.8)1.3%—Linksys E5600 Firmware23/12/202517/6/2026
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
AnalizadaCrítica (9.8)1.2%—Netgear Ex8000 Firmware23/12/202517/6/2026
Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.
AnalizadaMedia (6.5)0.90%—Netgear Ex8000 Firmware23/12/202517/6/2026
Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
ModificadaAlta (7.5)0.43%💥 PoCXiongmaitech Xm530v200 X6-weq 8M Firmware22/12/20255/7/2026
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
ModificadaCrítica (9.8)0.74%💥 PoCXiongmaitech Xm530v200 X6-weq 8M Firmware22/12/20255/7/2026
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling…