Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

26.338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)0.87%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202525/9/2026
Se identificó una vulnerabilidad en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Esto afecta a la función AP_get_wired_clientlist_setClientsName del archivo mod_form.so. La manipulación del argumento clientsname_0 conduce a un desbordamiento de búfer…
AnalizadaAlta (7.4)0.87%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202525/9/2026
Una vulnerabilidad fue encontrada en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Afectada por esta vulnerabilidad es la función AP_get_wireless_clientlist_setClientsName del archivo mod_form.so. Realizar la manipulación del argumento clientsname_0…
ModificadaAlta (7.4)10%—Zspace Q2C NAS Firmware5/12/202525/9/2026
Una vulnerabilidad ha sido identificada en ZSPACE Q2C NAS hasta 1.1.0210050. Afectada por este problema es la función zfilev2_api.OpenSafe del archivo /v2/file/safe/open del componente HTTP POST Request Handler. Esta manipulación del argumento safe_dir causa inyección de comandos. Es posible iniciar el ataque…
ModificadaAlta (7.4)12%—Zspace Q2C NAS Firmware5/12/202525/9/2026
Una falla de seguridad ha sido descubierta en ZSPACE Q2C NAS hasta la versión 1.1.0210050. Esta vulnerabilidad afecta a la función zfilev2_api.SafeStatus del archivo /v2/file/safe/status del componente HTTP POST Request Handler. La manipulación del argumento safe_dir resulta en inyección de comandos. El ataque puede…
ModificadaAlta (7.4)12%—Zspace Q2C NAS Firmware5/12/202525/9/2026
Se identificó una vulnerabilidad en ZSPACE Q2C NAS hasta la versión 1.1.0210050. Afecta a la función zfilev2_api.CloseSafe del archivo /v2/file/safe/close del componente HTTP POST Request Handler. La manipulación del argumento safe_dir conduce a una inyección de comandos. El ataque puede llevarse a cabo de forma…
AnalizadaBaja (2)20%—Edimax Br-6478ac V3 Firmware5/12/202517/6/2026
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early…
AnalizadaBaja (2)20%—Edimax Br-6478ac V3 Firmware5/12/202517/6/2026
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was…
ModificadaMedia (4.3)0.23%—Fanvil X210 Firmware5/12/20255/7/2026
File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.
ModificadaCrítica (9.6)0.44%—Fanvil X210 Firmware5/12/20255/7/2026
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
ModificadaMedia (5.1)2.8%—Fanvil X210 Firmware5/12/20255/7/2026
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.
AnalizadaBaja (2)17%—Edimax Br-6478ac V3 Firmware5/12/202517/6/2026
A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be…
ModificadaAlta (7.5)2.9%—Fanvil X210 Firmware5/12/202525/9/2026
Una vulnerabilidad de desbordamiento de búfer en dispositivos Fanvil x210 2.12.20 permite a los atacantes causar una denegación de servicio o potencialmente ejecutar comandos arbitrarios a través de una solicitud POST especialmente diseñada al endpoint /cgi-bin/webconfig?page=upload&action=submit.
ModificadaAlta (8.3)0.81%—Fanvil X210 Firmware5/12/202525/9/2026
Vulnerabilidad de salto de directorio en Fanvil x210 V2 2.12.20 permite a atacantes no autenticados en la red local almacenar archivos en ubicaciones arbitrarias y potencialmente modificar la configuración del sistema u otros impactos no especificados.
AnalizadaMedia (6.9)0.30%—Mersive Solstice POD Firmware4/12/202517/6/2026
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
ModificadaAlta (7.6)0.29%—Jxlindia JXL 9 Inch CAR Android Double DIN Player Firmware4/12/20255/7/2026
An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.
AnalizadaAlta (8.4)0.38%—Genexis Platinum 4410 Firmware4/12/202517/6/2026
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout. When an administrator logs out, the session…
ModificadaCrítica (9.8)2.0%—Allnet All-rut22gw Firmware4/12/20255/7/2026
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.
ModificadaCrítica (9.8)8.5%—Allnet All-rut22gw Firmware4/12/20255/7/2026
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
AnalizadaCrítica (9.8)0.57%—Waveshare Rs232/485 TO Wifi ETH (B) Firmware4/12/202517/6/2026
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password and username as blank values, allowing attackers to bypass authentication.
AnalizadaMedia (5.7)0.31%—Waveshare Rs232/485 TO Wifi ETH (B) Firmware4/12/202517/6/2026
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.
AnalizadaAlta (7.4)0.81%—H3C Magic B0 Firmware4/12/202517/6/2026
A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.…
AnalizadaAlta (7.5)0.28%—Waveshare Rs232/485 TO Wifi ETH (B) Firmware4/12/202517/6/2026
A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation frames to be broadcast without…
AnalizadaAlta (7.5)0.26%—Waveshare Rs232/485 TO Wifi ETH (B) Firmware4/12/202517/6/2026
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext.
AnalizadaCrítica (9.8)0.50%—Thermofisher ION Torrent Onetouch 2 Firmware4/12/202517/6/2026
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127.0.0.1 and…
AnalizadaCrítica (9.8)0.46%—Thermofisher ION Torrent Onetouch 2 Firmware4/12/202517/6/2026
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can…