Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.30% | — | Netgear Nighthawk RAXAI | 14/7/2026 | 15/7/2026 | A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router. | |
| Aplazada | Media (4.9) | 0.15% | — | Netgear Xr1000AINetgear NighthawkAI | 14/7/2026 | 15/7/2026 | A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device. | |
| Modificada | Alta (8.8) | 1.2% | — | Netgear Nighthawk Ax1800 FirmwareNetgear Nighthawk Ax2400 FirmwareNetgear Nighthawk Ax3000 FirmwareNetgear Nighthawk Ax5400 Firmware+2 | 16/12/2022 | 17/6/2026 | The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication. | |
| Modificada | Media (6.5) | 2.0% | — | Netgear Nighthawk R7000 Firmware | 2/11/2020 | 17/6/2026 | The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim visits an attacker-controlled web site with a modern browser, aka NAT Slipstreaming. This occurs because the ALG takes… | |
| Modificada | Media (6.1) | 0.84% | — | Netgear Nighthawk X10-r9000 Firmware | 24/2/2020 | 17/6/2026 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname field, an attacker may execute stored XSS attacks against this device. When the malicious DHCP request is received, the device will generate a log entry containing the malicious hostname. This log entry… | |
| Modificada | Media (6.1) | 0.97% | — | Netgear Nighthawk X10-r9000 Firmware | 24/2/2020 | 17/6/2026 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by supplying a malicious X-Forwarded-For header while performing an incorrect login attempt. The value supplied by this header will be inserted into administrative logs, found at Advanced… | |
| Modificada | Crítica (9.8) | 2.3% | — | Netgear Nighthawk X10-r9000 Firmware | 24/2/2020 | 17/6/2026 | In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced QoS being enabled, and a valid… | |
| Modificada | Crítica (9.1) | 0.73% | — | Netgear Nighthawk X10-r9000 Firmware | 24/2/2020 | 17/6/2026 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of… | |
| Modificada | Media (5) | 1.7% | — | Data General DG UXNCR Mp-rasSGI IrixIBM AIX+6 | 24/4/1996 | 16/6/2026 | Delete or create a file via rpc.statd, due to invalid information. |