Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.60% | — | Citrix Gateway FirmwareAI | 4/9/2026 | 8/9/2026 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | |
| En análisis | Media (6.1) | 0.27% | — | UI Unifi OS ServerUI Unifi Dream Machine Beast FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+26 | 2/7/2026 | 9/7/2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Dream Machine Beast FirmwareUI Enterprise Fortress Gateway FirmwareUI Unifi Dream Router FirmwareUI Unifi Dream Wall Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.68% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Crítica (9.3) | 0.59% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. | |
| Analizada | Alta (7.7) | 0.59% | — | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information. | |
| Analizada | Crítica (10) | 46% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | |
| Analizada | Crítica (10) | 1.8% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+28 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | |
| Analizada | Crítica (10) | 0.74% | — | Itel Idgateway Firmware | 18/11/2025 | 17/6/2026 | The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and… | |
| Analizada | Media (5.3) | 0.42% | — | Cisco IOS XECisco Cgr1000 FirmwareCisco Ir510 Wpan FirmwareCisco Ic3000 Industrial Compute Gateway Firmware+3 | 7/5/2025 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the… | |
| Analizada | Alta (8.6) | 2.4% | — | Enphase IQ Gateway Firmware | 12/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x | |
| Analizada | Alta (8.7) | 2.5% | — | Enphase IQ Gateway Firmware | 12/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225. |