Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.65%—Tenda Fh303 FirmwareTenda A300 Firmware29/4/202617/6/2026
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect…
AnalizadaMedia (5.5)2.9%—Totolink Wa300 Firmware20/3/202617/6/2026
A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalizadaBaja (2.1)2.6%—Totolink Wa300 Firmware8/2/202617/6/2026
A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaBaja (2.1)2.6%—Totolink Wa300 Firmware6/1/202617/6/2026
A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and…
AnalizadaMedia (5.5)0.26%—Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+253/4/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is…
ModificadaAlta (8.8)0.32%—Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware22/5/202317/6/2026
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
ModificadaCrítica (9.8)0.46%—Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware22/5/202317/6/2026
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
ModificadaAlta (7.8)0.26%—Intel Xeon Gold 5315y FirmwareIntel Xeon Gold 5317 FirmwareIntel Xeon Gold 5318n FirmwareIntel Xeon Gold 5318s Firmware+6818/8/202217/6/2026
Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.8)0.25%—Dell EMC Powerscale Nodes A100 FirmwareDell EMC Powerscale Nodes S210 FirmwareDell EMC Powerscale Nodes X410 FirmwareDell EMC Powerscale Nodes H400 Firmware+1512/11/202117/6/2026
Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privileges. This also affects Compliance mode and for Compliance mode clusters, is a critical vulnerability. Dell EMC recommends applying the workaround at your earliest opportunity.
ModificadaAlta (7.5)1.8%—Netapp Fas26x0 FirmwareNetapp Fas27x0 FirmwareNetapp Fas8200 FirmwareNetapp AFF C190 Firmware+311/5/202017/6/2026
Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS).
ModificadaCrítica (9.8)7.1%—Granding Grand Ma300 Firmware13/1/202017/6/2026
Grand MA 300 allows a brute-force attack on the PIN.
ModificadaAlta (7.5)4.3%—Granding Grand Ma300 Firmware13/1/202017/6/2026
Grand MA 300 allows retrieval of the access PIN from sniffed data.
ModificadaAlta (8.8)0.98%—Cisco Spa300 FirmwareCisco Spa500 Firmware19/10/201717/6/2026
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web…
ModificadaAlta (7.5)3.0%—Cisco Spa300 FirmwareCisco Spa500 Firmware12/9/201617/6/2026
The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385.
ModificadaAlta (7.2)0.38%—Cisco Spa500 FirmwareCisco Spa300 Firmware15/12/201517/6/2026
The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.
ModificadaMedia (6.4)1.8%—Cisco Spa500 FirmwareCisco SPA 501g 8-line IP PhoneCisco SPA 502g 1-line IP PhoneCisco SPA 504g 4-line IP Phone+1121/3/201517/6/2026
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.