Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.55%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by…
ModificadaMedia (4.8)0.55%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by…
ModificadaMedia (4.8)0.55%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by…
ModificadaMedia (4.8)0.55%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by…
ModificadaMedia (4.8)0.72%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by…
ModificadaAlta (7.2)2.4%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input…
ModificadaAlta (7.2)2.4%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input…
ModificadaAlta (7.2)2.4%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input…
ModificadaAlta (7.2)2.4%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input…
ModificadaAlta (7.2)2.4%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input…
ModificadaAlta (7.2)2.2%—Cisco Rv110w FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w FirmwareCisco Rv215w Wireless-n VPN Router Firmware+113/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of…
ModificadaMedia (5.3)1.1%—Sagemcom F@st 3486 Router Firmware27/11/202017/6/2026
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running.
ModificadaAlta (8.8)0.63%—Lenovo Thinkpad Stack Wireless Router Firmware14/10/202017/6/2026
An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege.
ModificadaAlta (7.2)3.2%—Cisco Rv016 Multi-wan VPN FirmwareCisco Rv042 Dual WAN VPNCisco Rv042g Dual Gigabit WAN VPN FirmwareCisco Rv082 Dual WAN VPN Router Firmware+223/9/202017/6/2026
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands will be executed with root privileges. The…
ModificadaAlta (8.8)3.7%—Sagemcom F@st 5280 Router Firmware1/9/202017/6/2026
Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value…
ModificadaAlta (8.6)1.4%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware16/7/202017/6/2026
A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests.…
ModificadaCrítica (9.8)4.2%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware16/7/202017/6/2026
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause the device to reload, resulting in a denial of service (DoS)…
ModificadaAlta (8.8)3.2%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of…
ModificadaCrítica (9.8)42%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input data by the…
ModificadaCrítica (9.8)5.7%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management…
ModificadaAlta (7.5)2.7%—Evenroute Iqrouter Firmware21/4/202017/6/2026
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password…
ModificadaCrítica (9.8)3.3%—Evenroute Iqrouter Firmware21/4/202017/6/2026
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for…
ModificadaCrítica (9.8)3.1%—Evenroute Iqrouter Firmware21/4/202017/6/2026
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for…
ModificadaCrítica (9.8)2.1%—Evenroute Iqrouter Firmware21/4/202017/6/2026
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure…
ModificadaAlta (7.5)2.3%—Evenroute Iqrouter Firmware21/4/202017/6/2026
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for…