Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

26.338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.19%—Sony Snc-cx600w Firmware25/11/202517/6/2026
Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the product.
AnalizadaBaja (2.1)0.11%—Sony Snc-cx600w Firmware25/11/202517/6/2026
Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may be performed.
ModificadaMedia (6.8)0.29%—Blurams A31c Firmware24/11/20255/7/2026
An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.
AnalizadaMedia (6.5)0.16%—Magewell Ultra Encode Hdmi FirmwareMagewell Ultra Encode SDI FirmwareMagewell Ultra Encode Hdmi Plus FirmwareMagewell Ultra Encode SDI Plus Firmware+124/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
AnalizadaMedia (5.7)0.16%—Magewell PRO Convert Hdmi 4K Plus FirmwareMagewell PRO Convert Hdmi Plus FirmwareMagewell PRO Convert Hdmi TX FirmwareMagewell PRO Convert 12G SDI 4K Plus Firmware+924/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AnalizadaMedia (5.5)6.2%—Dlink Dir-852 Firmware23/11/20258/10/2026
Se identificó una vulnerabilidad en D-Link DIR-852 1.00. Este problema afecta a un procesamiento desconocido del archivo /gena.cgi. Dicha manipulación del argumento service conduce a una inyección de comandos. El ataque puede ejecutarse de forma remota. El exploit está disponible públicamente y podría ser utilizado.…
AplazadaAlta (8.6)0.18%💥 PoCARM Trusted Firmware-aAI23/11/202517/6/2026
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
AnalizadaAlta (7.4)0.70%—Dlink Dwr-m920 Firmware23/11/202517/6/2026
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed…
AnalizadaAlta (7.4)0.73%—Dlink Dir-822k Firmware23/11/202517/6/2026
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AnalizadaAlta (7.4)0.79%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.4)0.74%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
ModificadaAlta (7.5)0.23%—FS S3150-8t2f Firmware20/11/20255/7/2026
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were transmitted in cleartext using simple base64…
AnalizadaCrítica (9.8)1.0%—Ilevia EVE X1 Server Firmware20/11/202517/6/2026
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secure filtering on IP parameters
AnalizadaMedia (6.1)0.32%—Ilevia EVE X1 Server Firmware20/11/202517/6/2026
Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component
AnalizadaMedia (4.3)0.24%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
AnalizadaMedia (4.3)0.29%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.
AnalizadaMedia (4.3)2.4%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.
AnalizadaMedia (4.3)0.29%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.
AnalizadaMedia (4.3)0.25%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.
AnalizadaMedia (5.3)0.33%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
AnalizadaCrítica (9.8)0.19%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.