Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.24% | — | Sound4 Playout Ula8 FirmwareSound4 Stream X8 FirmwareSound4 Stream X4 FirmwareSound4 Stream X2 Firmware+11 | 22/12/2025 | 17/6/2026 | SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 0.88% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 1.9% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.9% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.1% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.1% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 2.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists… | |
| Modificada | Alta (7.2) | 2.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists… | |
| Modificada | Alta (7.2) | 6.2% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability… | |
| Modificada | Alta (7.2) | 6.2% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability… | |
| Modificada | Alta (7.2) | 4.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Modificada | Alta (7.2) | 3.7% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Modificada | Alta (7.2) | 4.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Analizada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the adm.cgi set_sys_adm() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Analizada | Media (5.3) | 0.79% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… | |
| Modificada | Alta (7.2) | 0.88% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… |