Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.29%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
AnalizadaAlta (8.8)0.35%—Netgear Wnr614 Firmware7/6/202417/6/2026
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
AnalizadaAlta (8.1)0.40%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
ModificadaMedia (4.8)0.27%—Netgear Wnr614 Firmware7/6/202417/6/2026
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
AnalizadaAlta (8.8)0.57%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
AnalizadaMedia (4)0.34%—Netgear Wnr614 Firmware6/6/202417/6/2026
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
ModificadaAlta (8.8)47%—Netgear Prosafe Network Management System6/6/202417/6/2026
NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The…
AnalizadaAlta (8.8)27%—Netgear Prosafe Network Management System23/5/202417/6/2026
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability.…
AnalizadaAlta (8.8)31%💥 PoCNetgear Prosafe Network Management Software 30023/5/202417/6/2026
NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within…
AnalizadaAlta (7.8)0.57%—Netgear Prosafe Network Management System23/5/202417/6/2026
NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the ability to execute low-privileged code on…
AplazadaCrítica (9.9)25%💥 PoCNetgear GenieAI14/5/202417/6/2026
A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
AnalizadaAlta (8.8)1.1%—Netgear Cax30 FirmwareNetgear Cax30s Firmware7/5/202417/6/2026
NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the…
AnalizadaMedia (6.5)0.33%—Netgear Xr1000 FirmwareNetgear Xr300 FirmwareNetgear D6220 FirmwareNetgear D6400 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (8.8)0.58%—Netgear Dc112a FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (8.8)0.55%—Netgear D7800 FirmwareNetgear Ex2700 FirmwareNetgear Ex6100 FirmwareNetgear Ex6150 Firmware+377/5/202417/6/2026
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of…
AnalizadaCrítica (9.6)53%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability.…
AnalizadaAlta (8.8)54%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability.…
AnalizadaAlta (8.8)53%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific…
AnalizadaAlta (8.8)0.76%—Netgear Cax30 Firmware3/5/202417/6/2026
NETGEAR CAX30 SSO Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the sso…
AnalizadaAlta (8.8)14%—Netgear Rbr760 Firmware3/5/202417/6/2026
NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR Orbi 760 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the…
AnalizadaAlta (8.8)62%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DHCP…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service.…
AnalizadaMedia (6.8)0.83%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaAlta (8.8)1.4%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the…