Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.78% | — | Tenda I6 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda I6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Tenda i6 1.0.0.9(3857). It has been classified as critical. Affected is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to launch the attack remotely.… | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda I6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda I6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability has been found in Tenda i6 1.0.0.9(3857) and classified as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda I6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda i6 1.0.0.9(3857). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component httpd. The manipulation of the argument ping1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (8.8) | 0.96% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.2% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi… | |
| Modificada | Alta (7.5) | 1.3% | — | Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+358 | 7/12/2023 | 9/7/2026 | A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information. | |
| Modificada | Alta (7.5) | 0.77% | — | Tenda I6 Firmware | 30/11/2023 | 17/6/2026 | Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet. | |
| Modificada | Alta (7.5) | 0.77% | — | Tenda I6 Firmware | 30/11/2023 | 17/6/2026 | Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget. | |
| Modificada | Alta (7.8) | 0.39% | — | Supermicro X12dai-n6 FirmwareSupermicro X12ddw-a6 FirmwareSupermicro X12dgo-6 FirmwareSupermicro X12dgq-r Firmware+267 | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable. | |
| Modificada | Crítica (9.8) | 2.1% | — | Supermicro H12dst-b FirmwareSupermicro X13dai-t FirmwareSupermicro X13ddw-a FirmwareSupermicro X13deg-oa Firmware+161 | 31/7/2023 | 17/6/2026 | A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC. | |
| Modificada | Media (5.5) | 0.15% | — | Supermicro X11ssl-cf FirmwareSupermicro X11dac FirmwareSupermicro X11dai-n FirmwareSupermicro X11ddw-l Firmware+142 | 7/4/2023 | 9/7/2026 | Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions. |