Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.54% | — | RSA Archer | 29/1/2021 | 17/6/2026 | Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks. | |
| Modificada | Media (5.4) | 0.81% | — | RSA Archer | 29/1/2021 | 17/6/2026 | Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers,… | |
| Modificada | Crítica (9.8) | 7.6% | 💥 PoC | Tp-link Wa901nd FirmwareTp-link Archer C5 FirmwareTp-link Archer C7 FirmwareTp-link Mr3420 Firmware+23 | 26/12/2020 | 17/6/2026 | A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND,… | |
| Modificada | Media (6.1) | 0.66% | — | Tp-link Archer C9 Firmware | 21/11/2020 | 17/6/2026 | UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a crafted USB drive into the router. | |
| Modificada | Media (6.1) | 0.83% | — | RSA Archer | 18/11/2020 | 17/6/2026 | RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application. | |
| Modificada | Media (6.2) | 1.1% | — | Tp-link Archer A7 Firmware | 6/11/2020 | 17/6/2026 | UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access, to execute arbitrary code after plugging a crafted USB drive into the router. | |
| Modificada | Alta (7.5) | 15% | 💥 PoC | UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+213 | 8/6/2020 | 17/6/2026 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | |
| Modificada | Media (6.1) | 0.75% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used… | |
| Modificada | Media (6.1) | 0.70% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system. | |
| Modificada | Alta (8.8) | 0.46% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the… | |
| Modificada | Media (6.1) | 0.86% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the… | |
| Modificada | Media (4.3) | 0.80% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information. | |
| Modificada | Alta (7.2) | 2.2% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed. | |
| Modificada | Media (5.5) | 0.72% | — | RSA Archer | 4/5/2020 | 17/6/2026 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Tp-link Archer C50 | 25/3/2020 | 17/6/2026 | TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field. | |
| Modificada | Media (5.4) | 0.92% | — | Archerysec Archery | 26/12/2019 | 17/6/2026 | In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page. | |
| Modificada | Crítica (9.8) | 1.5% | — | RSA Archer | 18/9/2019 | 17/6/2026 | RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts. | |
| Modificada | Media (6.5) | 1.1% | — | RSA Archer | 18/9/2019 | 17/6/2026 | RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions. | |
| Modificada | Alta (8.8) | 0.91% | — | Tp-link Archer C3200 V1 FirmwareTp-link Archer C2 V1 Firmware | 27/8/2019 | 17/6/2026 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert… | |
| Modificada | Alta (8.8) | 0.97% | — | Tp-link Archer C3200 V1 FirmwareTp-link Archer C2 V1 Firmware | 27/8/2019 | 17/6/2026 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router… | |
| Modificada | Alta (8.8) | 0.97% | — | Tp-link Archer C3200 V1 FirmwareTp-link Archer C2 V1 Firmware | 27/8/2019 | 17/6/2026 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK… | |
| Modificada | Crítica (9.8) | 3.4% | — | Tp-link Archer C1200 Firmware | 17/7/2019 | 17/6/2026 | CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server. | |
| Modificada | Crítica (9.8) | 3.4% | — | Tp-link Archer C1200 Firmware | 17/7/2019 | 17/6/2026 | CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening… | |
| Modificada | Media (6.1) | 0.98% | — | Tp-link Archer Cr700 Firmware | 15/5/2019 | 17/6/2026 | TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contains the base64 encoded username and password. | |
| Modificada | Alta (7.8) | 0.38% | — | RSA Archer GRC Platform | 13/3/2019 | 17/6/2026 | RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks. |