Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.8)0.19%—Netgear Xr1000 FirmwareNetgear Xr1000v2 FirmwareNetgear Xr500 Firmware8/9/202611/9/2026
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality…
AnalizadaMedia (4.9)1.1%—Netgear Ms90 FirmwareNetgear Rax20 FirmwareNetgear Rax200 FirmwareNetgear Rax35 Firmware+2311/8/20269/9/2026
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
AnalizadaBaja (1.9)0.51%—Netgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 Firmware+1511/8/20269/9/2026
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+1611/8/20269/9/2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
AnalizadaBaja (1.9)0.22%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+159/6/202623/7/2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
AnalizadaMedia (6.1)0.24%—Netgear Xr1000v2 Firmware13/1/202617/6/2026
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.
AplazadaAlta (8.1)0.69%—Netgear Xr1000AINetgear Xr1000v2AINetgear Xr500AI5/2/202517/6/2026
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
ModificadaAlta (7.4)0.57%—Netgear Wnr612v2 FirmwareNetgear Dgn1000v3 FirmwareNetgear D6100 FirmwareNetgear Wnr1000v2 Firmware+52/2/202317/6/2026
An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification.…
ModificadaAlta (8.8)0.40%—Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+14025/8/202217/6/2026
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
ModificadaCrítica (9.1)1.8%—Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+14223/9/202117/6/2026
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory…
ModificadaMedia (5.4)0.55%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1030/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaAlta (7.6)0.63%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1430/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaMedia (5.4)0.55%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1030/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaCrítica (9.4)1.6%—Netgear Ac2100 FirmwareNetgear Ac2400 FirmwareNetgear Ac2600 FirmwareNetgear Cbk40 Firmware+12330/12/202017/6/2026
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D6000 before 1.0.0.80, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D7800…
ModificadaCrítica (9.8)1.3%—Netgear Cbr40 FirmwareNetgear D6220 FirmwareNetgear D6400 FirmwareNetgear D7000v2 Firmware+6530/12/202017/6/2026
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D8500 before 1.0.3.50, DC112A before 1.0.0.48, DGN2200v4 before 1.0.0.114, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62,…
ModificadaAlta (8.1)1.7%—Netgear Ac1450 FirmwareNetgear D8500 FirmwareNetgear Dc112a FirmwareNetgear Jndr3000 Firmware+299/10/201917/6/2026
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200,…
ModificadaAlta (8.8)2.5%—Cisco IOSCisco Cloud Services Router 1000v FirmwareCisco Integrated Services Virtual Router Firmware25/9/201917/6/2026
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
AnalizadaCrítica (9.8)83%⚠ Explotación activaNetgear D6100 FirmwareNetgear D7000 FirmwareNetgear D7800 FirmwareNetgear Jnr1010v2 Firmware+2430/1/201717/6/2026
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
AnalizadaAlta (8.1)89%⚠ Explotación activaNetgear R6200 FirmwareNetgear R6300 FirmwareNetgear Vegn2610 FirmwareNetgear Ac1450 Firmware+917/1/201717/6/2026
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set,…
ModificadaMedia (6.5)1.0%—Cisco Nexus 1000v Intercloud Firmware14/12/201617/6/2026
A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1).
AnalizadaAlta (8.8)88%⚠ Explotación activaCisco PIX Firewall SoftwareCisco Adaptive Security Appliance SoftwareCisco ASA 1000v Cloud Firewall Software18/8/201617/6/2026
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151…
ModificadaAlta (8.6)1.8%—Netgear Wnr1000v3 FirmwareNetgear Wnr1000v327/12/201517/6/2026
NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
ModificadaMedia (6.1)0.89%—Cisco Nx-osCisco San-osCisco MDS 9000Cisco 1000v2/9/201517/6/2026
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause…
ModificadaMedia (5)3.0%—Cisco Nx-osCisco Nexus 1000vCisco MDS 9000 Nx-os12/6/201517/6/2026
The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(0)ZN(99.67) on Nexus 3000 devices allows remote attackers…
ModificadaMedia (4.3)1.2%—Cisco Nexus 1000v Intercloud20/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq90524.