Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)1.0%—Tenda AC9 Firmware10/4/202617/6/2026
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.4)1.0%—Tenda AC9 Firmware10/4/202617/6/2026
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (7.3)0.70%—Tenda AC9 Firmware8/2/202617/6/2026
A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based buffer overflow. The attack may be launched remotely. The…
AnalizadaAlta (7.3)0.70%—Tenda AC9 Firmware8/2/202617/6/2026
A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
AnalizadaMedia (5.5)0.68%—Tenda AC9 Firmware9/12/202517/6/2026
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (4.9)0.43%—Dell Idrac9 FirmwareDell Idrac10 Firmware6/11/202517/6/2026
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')…
AnalizadaMedia (4.9)0.31%—Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+10825/9/202517/6/2026
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (7.5)0.40%—Tenda AC9 Firmware23/9/202517/6/2026
Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
AnalizadaMedia (6.5)0.98%—Tenda AC9 Firmware23/9/202517/6/2026
OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
AnalizadaAlta (7.4)4.2%—Tenda AC9 FirmwareTenda Ac15 Firmware15/9/202517/6/2026
A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be…
AnalizadaBaja (2.1)8.7%—Tenda AC9 FirmwareTenda Ac15 Firmware15/9/202517/6/2026
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalizadaBaja (1.1)0.14%—Tenda AC9 Firmware31/8/202517/6/2026
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high.…
AnalizadaBaja (2.1)0.30%—Tenda AC9 Firmware9/6/202517/6/2026
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.4)0.96%—Tenda AC9 Firmware8/6/202517/6/2026
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The…
AnalizadaAlta (7.4)0.99%—Tenda AC9 Firmware7/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched…
AnalizadaBaja (2.1)2.7%—Tenda AC9 Firmware7/6/202517/6/2026
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has…
AnalizadaCrítica (9.8)1.7%—Tenda AC9 Firmware5/5/202517/6/2026
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
AnalizadaCrítica (9.8)1.9%—Tenda AC9 Firmware2/5/202517/6/2026
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaCrítica (9.8)1.9%—Tenda AC9 Firmware2/5/202517/6/2026
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaCrítica (9.8)1.1%—Tenda AC9 Firmware23/4/202517/6/2026
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.
AnalizadaCrítica (9.8)0.92%—Tenda AC9 Firmware23/4/202517/6/2026
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
AnalizadaCrítica (9.8)0.92%—Tenda AC9 Firmware23/4/202517/6/2026
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
AnalizadaAlta (7.1)0.56%—Tenda AC9 Firmware14/3/202517/6/2026
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
ModificadaCrítica (9.8)0.90%—Tenda AC9 Firmware14/3/202517/6/2026
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
ModificadaCrítica (9.8)0.90%—Tenda AC9 Firmware14/3/202517/6/2026
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.