Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3238▲ 694 respecto a la semana anterior
Críticas / altas1520▲ 133 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

26.338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)3.9%—Tenda Ac21 Firmware20/11/202517/6/2026
A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.4)3.9%—Tenda Ac21 Firmware20/11/202517/6/2026
A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)20%—UTT 750w Firmware20/11/202517/6/2026
A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argument policyNames leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly…
AnalizadaAlta (7.3)7.6%—Dlink Dir-868l Firmware19/11/202517/6/2026
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.
AnalizadaCrítica (9.8)0.88%—Qvidium Opera11 Firmware19/11/202517/6/2026
The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker can exploit this vulnerability by sending a specially crafted GET request with a malicious parameter to inject arbitrary…
AnalizadaMedia (6.5)0.36%—Gatesair Flexiva Lx100 FirmwareGatesair Flexiva Lx300 FirmwareGatesair Flexiva Lx600 FirmwareGatesair Flexiva Lx1000 Firmware19/11/202517/6/2026
GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any…
AnalizadaCrítica (9.8)0.55%—Newtec Celoxa504 FirmwareNewtec Celoxa820 Firmware19/11/202517/6/2026
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the…
AnalizadaAlta (7.5)0.41%—Elcaradio Star150 FirmwareElcaradio Bp1000 FirmwareElcaradio Star300 FirmwareElcaradio Star2000 Firmware+219/11/202517/6/2026
The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models, contains an information disclosure vulnerability allowing unauthenticated attackers to retrieve admin credentials and system settings via an unprotected /setup.xml endpoint. The…
AnalizadaAlta (7.5)0.24%—Bridgetech Vb288 Firmware19/11/202517/6/2026
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.
AnalizadaCrítica (9.8)7.0%—RVR Tex30lcd/s FirmwareRVR Tex50lcd/s FirmwareRVR Tex100lcd/s FirmwareRVR Tex150lcd/s Firmware+719/11/202517/6/2026
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system…
AnalizadaCrítica (9.8)0.53%—Dasannetworks Ds2924 Firmware19/11/202517/6/2026
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
ModificadaAlta (7.5)0.37%—Bridgetech Vb220 FirmwareBridgetech Vb120 FirmwareBridgetech Vb330 FirmwareBridgetech Vb440 Firmware+119/11/202517/6/2026
An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd…
ModificadaAlta (7.4)0.69%—Tenda Ch22 Firmware19/11/202517/6/2026
A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing a manipulation of the argument chkHz results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AnalizadaCrítica (10)0.72%—Itel Idenc Firmware19/11/202517/6/2026
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and…
AnalizadaCrítica (9.8)0.75%—Axeltechnology Streamermax MK II Firmware19/11/202517/6/2026
The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system…
AnalizadaCrítica (9.1)0.53%—Axeltechnology Puma Firmware19/11/202517/6/2026
The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to…
AnalizadaAlta (7.2)0.46%—Sound4 First Firmware19/11/202517/6/2026
The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
AnalizadaAlta (7.5)0.43%—Itel Iso-fm Firmware19/11/202517/6/2026
The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system…
AnalizadaCrítica (9.8)0.64%—Axeltechnology Wolf1ms FirmwareAxeltechnology Wolf2ms Firmware19/11/202517/6/2026
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system…
AplazadaCrítica (9.3)0.34%—Vivotek Device FirmwareAI19/11/202517/6/2026
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
AnalizadaMedia (5.4)0.28%—Dbbroadcast Mozart Next 100 FirmwareDbbroadcast Mozart Next 1000 FirmwareDbbroadcast Mozart Next 2000 FirmwareDbbroadcast Mozart Next 30 Firmware+1818/11/202517/6/2026
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially…
AnalizadaCrítica (9.8)0.56%—Itel ID MUX Firmware18/11/202517/6/2026
The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks…
AnalizadaCrítica (10)0.74%—Itel Idgateway Firmware18/11/202517/6/2026
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and…
AnalizadaAlta (7.2)0.46%—Sound4 Impact Firmware18/11/202517/6/2026
The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
AnalizadaCrítica (9.8)0.76%—Dbbroadcast Mozart Next 100 FirmwareDbbroadcast Mozart Next 1000 FirmwareDbbroadcast Mozart Next 2000 FirmwareDbbroadcast Mozart Next 30 Firmware+1818/11/202517/6/2026
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The uploaded file is stored in…