Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.66%—Contec Ec1000AI14/9/202616/9/2026
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
AplazadaMedia (4.8)0.24%—Contec Ec1000 SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AnalizadaMedia (6.9)0.41%—Tp-link Tapo C100 FirmwareTp-link Tapo C101 Firmware19/8/20264/9/2026
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger…
AnalizadaAlta (7.1)0.38%—Tp-link Tapo C100 FirmwareTp-link Tapo C101 Firmware19/8/20264/9/2026
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video…
AplazadaCrítica (9.3)1.1%—Trendnet Tew-wlc100AI18/8/202620/8/2026
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is…
AplazadaAlta (8.6)0.60%—Trendnet Tew-wlc100pAI18/8/202620/8/2026
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network.…
AplazadaMedia (6.3)0.18%—Trendnet Tew-wlc100AI15/8/202620/8/2026
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The…
AplazadaBaja (2)3.4%—Comfast Cf-ac100AI20/3/202617/6/2026
A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-config?method=SET&section=update_interface_png. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be…
AplazadaBaja (2)3.4%—Comfast Cf-ac100AI20/3/202617/6/2026
A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=wireless_device_dissoc. The manipulation results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was…
AplazadaBaja (2)3.4%—Comfast Cf-ac100AI20/3/202617/6/2026
A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The…
AnalizadaBaja (2)11%—Comfast Cf-ac100 Firmware9/3/202617/6/2026
A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Request Path Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be…
AnalizadaAlta (8.5)0.37%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202517/6/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer…
AnalizadaAlta (8.7)0.33%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202517/6/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer…
AnalizadaCrítica (10)0.35%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202517/6/2026
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.
AnalizadaAlta (7.1)0.26%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the parameter is too large, it will access memory beyond the limits.
AnalizadaAlta (8.5)0.33%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a…
AnalizadaAlta (8.5)1.0%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.
AnalizadaAlta (8.5)0.37%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using 'system()'. This allows an attacker to…
AnalizadaAlta (8.5)0.37%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer…
AnalizadaAlta (8.5)0.58%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code…
AnalizadaAlta (8.5)0.37%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without checking the length. An attacker can provide an…
AnalizadaAlta (8.6)0.14%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This…
AnalizadaCrítica (9.4)1.3%—Circutor Sge-plc1000 FirmwareCircutor Sge-plc50 Firmware2/12/202525/9/2026
Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The…
AnalizadaAlta (7.5)0.39%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+131/12/202517/6/2026
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
AnalizadaAlta (7.5)0.41%—Sick Tloc100-100 Firmware27/10/202517/6/2026
An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.