Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3082▲ 502 respecto a la semana anterior
Críticas / altas1460▲ 59 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

26.338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.53%—Dlink Dsl-124 Firmware22/12/202517/6/2026
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network…
AnalizadaAlta (8.7)0.51%—Dbbroadcast SFT DAB 600/c Firmware22/12/202517/6/2026
Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with…
AnalizadaCrítica (9.3)0.51%—Dbbroadcast SFT DAB 600/c Firmware22/12/202517/6/2026
Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper…
AnalizadaCrítica (9.3)0.64%—Dbbroadcast SFT DAB 600/c Firmware22/12/202517/6/2026
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper…
AnalizadaCrítica (9.3)0.51%—Dbbroadcast SFT DAB 600/c Firmware22/12/202517/6/2026
Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify…
AnalizadaAlta (8.6)0.24%—Sound4 Playout Ula8 FirmwareSound4 Stream X8 FirmwareSound4 Stream X4 FirmwareSound4 Stream X2 Firmware+1122/12/202517/6/2026
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem…
ModificadaAlta (8.8)0.98%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining…
AnalizadaCrítica (9.3)3.4%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to…
ModificadaAlta (8.8)1.2%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Stream Extension+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal…
ModificadaMedia (5.1)0.19%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when…
ModificadaCrítica (9.3)0.74%—Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized…
AnalizadaCrítica (9.3)0.85%—Sound4 Stream ExtensionSound4 WM2 FirmwareSound4 BIG Voice2 FirmwareSound4 BIG Voice4 Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
AnalizadaAlta (8.8)0.34%💥 PoCLSC Smart Connect Indoor IP Camera Firmware22/12/202517/6/2026
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
AnalizadaCrítica (9.2)0.32%—Sharp Mp-01 Firmware22/12/202517/6/2026
Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the…
AnalizadaCrítica (9.5)0.20%—Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+2222/12/202517/6/2026
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.
AnalizadaAlta (8.4)0.41%—Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+2222/12/202517/6/2026
Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.
AnalizadaCrítica (9.2)0.41%—Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+2222/12/202517/6/2026
Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.
AnalizadaCrítica (9.1)0.40%—Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+2222/12/202517/6/2026
Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.
AnalizadaAlta (7.5)0.22%—Deltaww Dvp15mc11t Firmware22/12/202517/6/2026
Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.
AnalizadaAlta (8.9)1.0%—Tenda Wh450 Firmware22/12/202517/6/2026
A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.5)0.55%—Tenda Wh450 Firmware22/12/202517/6/2026
A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
AnalizadaAlta (8.9)1.0%—Tenda Wh450 Firmware22/12/202517/6/2026
A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.9)0.97%—Tenda Wh450 Firmware22/12/202517/6/2026
A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has…
AnalizadaAlta (7.4)0.75%—Tenda Fh1201 FirmwareTenda Fh1206 Firmware21/12/202517/6/2026
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack is possible to be carried out remotely. The…
AnalizadaAlta (7.4)0.74%—Tenda Fh1201 Firmware21/12/202528/9/2026
Una vulnerabilidad ha sido encontrada en Tenda FH1201 1.2.0.14(408). Afectada es la función sprintf del archivo /goform/SetIpBind. Tal manipulación del argumento page conduce a un desbordamiento de búfer basado en pila. El ataque puede ser realizado desde remoto. El exploit ha sido divulgado al público y puede ser…