Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.47% | — | Beward N100AI | 24/12/2025 | 17/6/2026 | Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP stream by exploiting the lack of authentication in the video access mechanism. | |
| Aplazada | Media (5.1) | 0.16% | — | Beward N100AI | 24/12/2025 | 17/6/2026 | Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft a malicious web page with a hidden form to add an admin user by tricking a logged-in user into submitting the form. | |
| Aplazada | Alta (7.1) | 19% | — | Beward N100AI | 24/12/2025 | 17/6/2026 | Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying… | |
| Analizada | Alta (8.6) | 6.3% | — | Netgear Dgn1000b Firmware | 1/8/2025 | 16/6/2026 | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST… | |
| Aplazada | Crítica (9.4) | 1.7% | — | Beward N100AI | 26/6/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via the ServerName and TimeZone parameters in the servetest CGI page. An attacker with access to the web interface can inject arbitrary system commands into these parameters, which are unsafely embedded… | |
| Modificada | Crítica (9.8) | 30% | — | Netgear Dgn1000 Firmware | 10/1/2025 | 17/6/2026 | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at… | |
| Analizada | Alta (8.8) | 14% | — | Netgear Dgn1000ww Firmware | 23/8/2024 | 17/6/2026 | An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page | |
| Modificada | Alta (8) | 0.68% | — | Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+20 | 17/7/2023 | 17/6/2026 | A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.00 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.00… | |
| Modificada | Media (6.5) | 0.30% | — | Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+20 | 17/7/2023 | 17/6/2026 | A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware… | |
| Modificada | Alta (8.8) | 0.76% | — | Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+11 | 17/7/2023 | 17/6/2026 | A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device. | |
| Modificada | Alta (8) | 0.68% | — | Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+18 | 17/7/2023 | 17/6/2026 | A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.60 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.60 through… | |
| Modificada | Alta (8.8) | 9.9% | — | Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+18 | 17/7/2023 | 17/6/2026 | A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36… | |
| Modificada | Alta (8.8) | 0.34% | — | Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+18 | 17/7/2023 | 17/6/2026 | A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware… | |
| Modificada | Alta (8.8) | 0.40% | — | Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+18 | 17/7/2023 | 17/6/2026 | The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36, USG FLEX 50(W) series firmware versions 5.10 through 5.36, USG20(W)-VPN series firmware versions 5.10 through 5.36, and VPN series firmware… | |
| Analizada | Crítica (9.8) | 29% | ⚠ Explotación activa | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+19 | 24/5/2023 | 17/6/2026 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series… | |
| Analizada | Crítica (9.8) | 28% | ⚠ Explotación activa | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+19 | 24/5/2023 | 17/6/2026 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series… | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests… | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Zyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+15 | 25/4/2023 | 17/6/2026 | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS… | |
| Modificada | Alta (8.8) | 1.5% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+15 | 24/4/2023 | 17/6/2026 | The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions… | |
| Modificada | Media (4.8) | 0.34% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+15 | 24/4/2023 | 17/6/2026 | The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which… | |
| Modificada | Media (6.5) | 0.77% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+47 | 24/4/2023 | 17/6/2026 | A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions… | |
| Modificada | Alta (7.5) | 0.88% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+14 | 24/4/2023 | 17/6/2026 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00… | |
| Modificada | Alta (8.1) | 0.69% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+14 | 24/4/2023 | 17/6/2026 | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly… | |
| Modificada | Alta (7.5) | 1.1% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+8 | 24/4/2023 | 17/6/2026 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote… |