Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.65% | — | Tenda Fh303 FirmwareTenda A300 Firmware | 29/4/2026 | 17/6/2026 | Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect… | |
| Analizada | Media (5.5) | 2.9% | — | Totolink Wa300 Firmware | 20/3/2026 | 17/6/2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 2.6% | — | Totolink Wa300 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 2.6% | — | Totolink Wa300 Firmware | 6/1/2026 | 17/6/2026 | A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and… | |
| Analizada | Media (5.5) | 0.26% | — | Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+25 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is… | |
| Modificada | Alta (8.8) | 0.32% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files. | |
| Modificada | Crítica (9.8) | 0.46% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel Xeon Gold 5315y FirmwareIntel Xeon Gold 5317 FirmwareIntel Xeon Gold 5318n FirmwareIntel Xeon Gold 5318s Firmware+68 | 18/8/2022 | 17/6/2026 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.8) | 0.25% | — | Dell EMC Powerscale Nodes A100 FirmwareDell EMC Powerscale Nodes S210 FirmwareDell EMC Powerscale Nodes X410 FirmwareDell EMC Powerscale Nodes H400 Firmware+15 | 12/11/2021 | 17/6/2026 | Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privileges. This also affects Compliance mode and for Compliance mode clusters, is a critical vulnerability. Dell EMC recommends applying the workaround at your earliest opportunity. | |
| Modificada | Alta (7.5) | 1.8% | — | Netapp Fas26x0 FirmwareNetapp Fas27x0 FirmwareNetapp Fas8200 FirmwareNetapp AFF C190 Firmware+3 | 11/5/2020 | 17/6/2026 | Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS). | |
| Modificada | Crítica (9.8) | 7.1% | — | Granding Grand Ma300 Firmware | 13/1/2020 | 17/6/2026 | Grand MA 300 allows a brute-force attack on the PIN. | |
| Modificada | Alta (7.5) | 4.3% | — | Granding Grand Ma300 Firmware | 13/1/2020 | 17/6/2026 | Grand MA 300 allows retrieval of the access PIN from sniffed data. | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco Spa300 FirmwareCisco Spa500 Firmware | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web… | |
| Modificada | Alta (7.5) | 3.0% | — | Cisco Spa300 FirmwareCisco Spa500 Firmware | 12/9/2016 | 17/6/2026 | The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385. | |
| Modificada | Alta (7.2) | 0.38% | — | Cisco Spa500 FirmwareCisco Spa300 Firmware | 15/12/2015 | 17/6/2026 | The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400. | |
| Modificada | Media (6.4) | 1.8% | — | Cisco Spa500 FirmwareCisco SPA 501g 8-line IP PhoneCisco SPA 502g 1-line IP PhoneCisco SPA 504g 4-line IP Phone+11 | 21/3/2015 | 17/6/2026 | The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482. |