Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.40%—Tp-link Kasa Ec70 FirmwareTp-link Kasa Ec71 Firmware15/7/20266/8/2026
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted…
AnalizadaAlta (7.2)12%⚠ Explotación activa💥 PoCSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
AnalizadaCrítica (10)6.8%⚠ Explotación activa💥 ExploitSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
AnalizadaAlta (7.1)0.13%—Tp-link Deco M5 Firmware14/7/20266/8/2026
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling…
AnalizadaAlta (7.8)0.30%—Microsoft Surface GO 2 1901 FirmwareMicrosoft Surface GO 2 1926 FirmwareMicrosoft Surface GO 2 1927 FirmwareMicrosoft Surface GO 3 1901 Firmware+2314/7/202624/7/2026
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.1)1.4%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account…
AnalizadaAlta (8.5)2.1%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges.…
AnalizadaAlta (8.6)0.84%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and…
Pendiente de análisisCrítica (9.2)0.43%—Cradlepoint 5380 5480 5580 Boot FirmwareAI14/7/202629/9/2026
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
AnalizadaMedia (6.8)0.85%—Dlink Dir-823g Firmware9/7/20263/9/2026
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high…
AnalizadaAlta (7.2)1.9%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to…
AnalizadaAlta (7)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 Firmware+176/7/20267/7/2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
AnalizadaAlta (8.8)0.11%—Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+1246/7/20267/7/2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+756/7/20267/7/2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
AnalizadaAlta (7.1)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+496/7/20268/7/2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+436/7/20267/7/2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1056/7/20267/7/2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
AnalizadaBaja (3.8)0.19%—Trustedfirmware Op-tee6/7/20267/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM implementation cause the authentication tag to be…
AnalizadaMedia (5.5)0.18%—Trustedfirmware Op-tee6/7/20267/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey…
AnalizadaBaja (3.8)0.15%—Trustedfirmware Op-tee6/7/20267/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function…