Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.51% | — | Netgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 Firmware+15 | 11/8/2026 | 9/9/2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | |
| Analizada | Baja (1.9) | 0.51% | — | Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+16 | 11/8/2026 | 9/9/2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | |
| Analizada | Media (4.9) | 0.35% | — | Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+27 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analizada | Media (4.3) | 0.24% | — | Netgear Cbr750 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 FirmwareNetgear Mr60 Firmware+31 | 9/6/2026 | 23/7/2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | |
| Analizada | Media (4.3) | 0.23% | — | Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+23 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. | |
| Analizada | Media (4.3) | 0.18% | — | Netgear Raxe450 FirmwareNetgear Raxe500 Firmware | 9/6/2026 | 23/7/2026 | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or… | |
| Analizada | Baja (1.9) | 0.22% | — | Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+15 | 9/6/2026 | 23/7/2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. | |
| Modificada | Alta (8.5) | 5.2% | — | Tp-link Archer Be450 FirmwareTp-link Archer Be7200 Firmware | 27/5/2026 | 17/6/2026 | An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console… | |
| Analizada | Media (4.4) | 0.29% | — | Netgear Rs700 FirmwareNetgear Rax54sv2 FirmwareNetgear Rax45v2 FirmwareNetgear Rax41v2 Firmware+14 | 9/12/2025 | 30/9/2026 | A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through… | |
| Analizada | Media (6.5) | 0.33% | — | Netgear Xr1000 FirmwareNetgear Xr300 FirmwareNetgear D6220 FirmwareNetgear D6400 Firmware+48 | 7/5/2024 | 17/6/2026 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Alta (8.8) | 0.58% | — | Netgear Dc112a FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 Firmware+48 | 7/5/2024 | 17/6/2026 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Modificada | Alta (8.8) | 0.52% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+119 | 25/10/2023 | 17/6/2026 | An authenticated XCC user can change permissions for any user through a crafted API command. | |
| Modificada | Alta (8.8) | 0.51% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |
| Modificada | Alta (8.8) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |
| Modificada | Media (5.9) | 0.45% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | |
| Modificada | Media (4.9) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured | |
| Modificada | Media (6.5) | 0.36% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. | |
| Modificada | Alta (8.8) | 0.50% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”. | |
| Modificada | Media (4.3) | 0.41% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |
| Modificada | Media (6.5) | 0.63% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Alta (8.8) | 5.7% | — | Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+40 | 15/11/2021 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. When parsing… | |
| Modificada | Alta (8.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Crítica (9.1) | 1.6% | — | Zyxel Lte4506-m606 FirmwareZyxel Lte7460-m608 FirmwareZyxel Wah7706 Firmware | 16/3/2021 | 17/6/2026 | The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS… | |
| Modificada | Alta (7.5) | 1.1% | — | Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+80 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. |