Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.43% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | |
| Analizada | Media (5.4) | 0.37% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | |
| Aplazada | Alta (8.8) | 0.34% | — | Carrier I-vu Gen5 RouterAIAutomatedlogic I-vu Gen5 RouterAI | 27/11/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.60% | — | Asus RouterAI | 25/11/2025 | 17/6/2026 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security… | |
| Aplazada | Alta (7.5) | 0.75% | — | Asus RouterAI | 25/11/2025 | 17/6/2026 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer to the 'Security Update for ASUS Router… | |
| Aplazada | Media (6.9) | 0.42% | — | Asus Router FirmwareAI | 25/11/2025 | 17/6/2026 | A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory… | |
| Aplazada | Alta (8.2) | 0.65% | — | Asus Router FirmwareAIWebdavAI | 25/11/2025 | 17/6/2026 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (7.5) | 0.38% | — | Apollo FederationAIApollo RouterAIAvirt RoverAI | 13/11/2025 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation… | |
| Aplazada | Alta (7.5) | 0.30% | — | Apollo Router CoreAI | 7/11/2025 | 17/6/2026 | Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that… | |
| Aplazada | Alta (7.5) | 0.34% | — | Apollo Router CoreAI | 6/11/2025 | 17/6/2026 | Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access controls. Router… | |
| Aplazada | Alta (7.5) | 0.31% | — | Italy Wireless Mini Router Wireless-n 300mAI | 30/10/2025 | 17/6/2026 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password. | |
| Aplazada | Crítica (10) | 0.30% | — | Mikrotik RouterosAIMikrotik SwosAI | 27/10/2025 | 17/6/2026 | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials. | |
| Aplazada | Crítica (9.9) | 0.60% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In… | |
| Aplazada | Media (5.3) | 0.58% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the… | |
| Aplazada | Alta (8.7) | 0.51% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate… | |
| Aplazada | Crítica (9.3) | 1.9% | — | Bytevalue Intelligent Flow Control RouterAI | 15/10/2025 | 17/6/2026 | BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Draytech Vigor RouterAI | 3/10/2025 | 17/6/2026 | An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption. | |
| Aplazada | Media (6.5) | 0.21% | 💥 PoC | Eachitaly Wireless Mini RouterAI | 29/9/2025 | 17/6/2026 | Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands. | |
| Aplazada | Alta (7.4) | 0.77% | — | Mikrotik RouterosAI | 25/9/2025 | 17/6/2026 | A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.… | |
| Aplazada | Media (5.1) | 0.49% | — | PPC 2k15x RouterAI | 16/9/2025 | 17/6/2026 | This vulnerability exist in PPC 2K15X Router, due to improper input validation for the Common Gateway Interface (CGI) parameters at its web management portal. A remote attacker could exploit this vulnerability by injecting malicious JavaScript into the vulnerable parameter, leading to a reflected Cross-Site Scripting… | |
| Analizada | Alta (7.1) | 0.84% | — | Qnap Qurouter | 29/8/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.5.1.060 and later | |
| Aplazada | Alta (8.1) | 0.30% | — | Claude-code-routerAI | 21/8/2025 | 17/6/2026 | claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this… | |
| Aplazada | Alta (8.8) | 22% | — | Kuwfi 4G Ac900 LTE RouterAI | 14/8/2025 | 17/6/2026 | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to… |