Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.54% | — | Buffalo Hgw-bl1500hmAI | 28/3/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an attacker may delete a file on the device or cause a denial of service… | |
| Aplazada | Baja (2.1) | 0.29% | — | Buffalo Hgw-bl1500hmAI | 28/3/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request… | |
| Aplazada | Alta (8.8) | 0.95% | — | HGW Bl1500hmAI | 28/3/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be… | |
| Aplazada | Media (6.5) | 0.69% | — | NEC Hgw-bl1500hmAI | 28/3/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP… | |
| Aplazada | Baja (3.6) | 0.20% | — | HGW Bl1500hmAI | 28/3/2025 | 17/6/2026 | Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of… | |
| Aplazada | Media (5.4) | 0.27% | — | HGW Bl1500hmAI | 28/3/2025 | 17/6/2026 | Cross-site scripting vulnerability exists in the NickName registration screen of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the… | |
| Aplazada | Media (6.5) | 0.36% | — | HGW Bl1500hmAI | 25/3/2024 | 17/6/2026 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell. | |
| Aplazada | Alta (8.8) | 0.36% | — | HGW Bl1500hmAI | 25/3/2024 | 17/6/2026 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings. | |
| Aplazada | Alta (8.8) | 0.62% | — | HGW Bl1500hmAI | 25/3/2024 | 17/6/2026 | HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command. |