Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.27% | — | Dell Idrac10 Firmware | 29/4/2026 | 17/6/2026 | Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access. | |
| Analizada | Alta (8.7) | 0.95% | — | Tenda Ac10 Firmware | 5/4/2026 | 24/7/2026 | A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected. | |
| Analizada | Media (5.5) | 0.71% | — | Tenda Ac10 Firmware | 5/4/2026 | 24/7/2026 | A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched… | |
| Analizada | Alta (8.7) | 0.84% | — | Tenda Ac10 Firmware | 5/4/2026 | 24/7/2026 | A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely. | |
| Analizada | Media (5.3) | 4.1% | — | Tenda Ac10 Firmware | 5/4/2026 | 24/7/2026 | A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected. | |
| Analizada | Media (6.5) | 0.38% | — | Tenda Ac10 Firmware | 17/12/2025 | 17/6/2026 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan. | |
| Analizada | Crítica (9.8) | 0.69% | — | Tenda Ac10 Firmware | 17/12/2025 | 17/6/2026 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan. | |
| Analizada | Media (4.9) | 0.43% | — | Dell Idrac9 FirmwareDell Idrac10 Firmware | 6/11/2025 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')… | |
| Analizada | Alta (7.4) | 0.90% | — | Tenda Ac10 Firmware | 3/11/2025 | 17/6/2026 | A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.3) | 0.24% | — | Tenda Ac10 Firmware | 28/8/2025 | 17/6/2026 | Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request. | |
| Analizada | Alta (7.5) | 0.39% | — | Tenda Ac10 Firmware | 28/8/2025 | 17/6/2026 | Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list_Info. | |
| Analizada | Media (5.3) | 0.51% | — | Tenda Ac10 Firmware | 28/8/2025 | 17/6/2026 | Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler. | |
| Analizada | Media (5.3) | 0.80% | — | Tenda Ac10 Firmware | 28/8/2025 | 25/9/2026 | An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet. | |
| Analizada | Media (5.3) | 0.59% | — | Tenda Ac10 Firmware | 28/8/2025 | 25/9/2026 | Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C. | |
| Analizada | Baja (1.1) | 0.21% | — | Tenda Ac10 Firmware | 21/8/2025 | 17/6/2026 | A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda Ac10 Firmware | 26/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /goform/RequestsProcessLaid. The manipulation of the argument device1D leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 0.83% | — | Tenda Ac10 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of the component HTTP Handler. The manipulation of the argument startIp/endIp leads to buffer overflow. It is possible to initiate the attack… | |
| Analizada | Alta (8.7) | 0.84% | — | Tenda Ac10 Firmware | 18/5/2025 | 17/6/2026 | A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. The manipulation of the argument getuid leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.4) | 0.27% | — | Tenda Ac10 Firmware | 12/5/2025 | 17/6/2026 | Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function. | |
| Analizada | Crítica (9.8) | 6.5% | — | Tenda Ac10 Firmware | 12/5/2025 | 17/6/2026 | Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter. | |
| Analizada | Alta (7.5) | 0.57% | — | Tenda Ac10 Firmware | 17/4/2025 | 17/6/2026 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2. | |
| Analizada | Alta (7.5) | 0.57% | — | Tenda Ac10 Firmware | 17/4/2025 | 17/6/2026 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2. | |
| Analizada | Alta (7.5) | 0.67% | — | Tenda Ac10 Firmware | 17/4/2025 | 17/6/2026 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2. | |
| Analizada | Media (4.6) | 0.26% | — | Tenda Ac10 Firmware | 15/4/2025 | 17/6/2026 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2. | |
| Analizada | Media (4.6) | 0.26% | — | Tenda Ac10 Firmware | 15/4/2025 | 17/6/2026 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2. |