Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.37% | — | Workos Authkit React RouterAI | 9/8/2025 | 17/6/2026 | The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the… | |
| Analizada | Media (5.9) | 0.21% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Media (5.9) | 0.21% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Alta (7.2) | 1.1% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to execute arbitrary code via unspecified vectors. | |
| Aplazada | Crítica (9.3) | 28% | 💥 Exploit | Netcore RouterAINetis RouterAI | 16/7/2025 | 17/6/2026 | A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated remote attacker can send specially crafted… | |
| Aplazada | Media (4.8) | 0.72% | 💥 Exploit | Mikrotik RouterosAI | 3/7/2025 | 17/6/2026 | A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a… | |
| Aplazada | Media (6.5) | 0.24% | — | Mikrotik RouterosAI | 30/6/2025 | 5/7/2026 | A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets. | |
| Aplazada | Crítica (9.4) | 3.9% | — | Wifisky 7-layer Flow Control RouterAI | 26/6/2025 | 17/6/2026 | A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the… | |
| Analizada | Alta (7.2) | 0.57% | — | Mikrotik Routeros | 25/6/2025 | 17/6/2026 | Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of remote IP… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Crítica (9.3) | 1.7% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Crítica (10) | 93% | 💥 Exploit | Linksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+2 | 24/6/2025 | 22/7/2026 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to… | |
| Analizada | Media (5.2) | 0.27% | — | Qnap Qurouter | 6/6/2025 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later | |
| Analizada | Baja (2.4) | 0.62% | — | Qnap Qurouter | 6/6/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and… | |
| Analizada | Alta (7.5) | 0.55% | — | Mikrotik Routeros | 29/5/2025 | 17/6/2026 | MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable. | |
| Analizada | Media (5.3) | 0.42% | — | Cisco IOS XECisco Cgr1000 FirmwareCisco Ir510 Wpan FirmwareCisco Ic3000 Industrial Compute Gateway Firmware+3 | 7/5/2025 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the… | |
| Aplazada | Alta (8.2) | 0.80% | 💥 PoC | React RouterAI | 25/4/2025 | 17/6/2026 | React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values of the data object passed to the HTML. This issue has been patched in version… | |
| Aplazada | Alta (7.5) | 20% | 💥 PoC | React RouterAI | 25/4/2025 | 17/6/2026 | React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system… | |
| Analizada | Alta (7.2) | 2.1% | — | Bectechnologies Router Firmware | 23/4/2025 | 17/6/2026 | BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, the existing… | |
| Analizada | Media (6.5) | 0.45% | — | Bectechnologies Router Firmware | 23/4/2025 | 17/6/2026 | BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The… | |
| Analizada | Media (5.3) | 0.91% | — | Bectechnologies Router Firmware | 23/4/2025 | 17/6/2026 | BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface.… | |
| Analizada | Media (6.5) | 0.49% | — | Bectechnologies Router Firmware | 23/4/2025 | 17/6/2026 | BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The specific flaw exists… | |
| Aplazada | Alta (7.5) | 0.56% | — | Apollo RouterAITarget CompilerAI | 9/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This… | |
| Aplazada | Alta (7.5) | 0.53% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, a vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan,… | |
| Aplazada | Alta (7.5) | 0.57% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, the operation limits plugin uses unsigned 32-bit integers to track limit counters (e.g. for a query's height). If a counter exceeded the… |