Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI | 4/8/2026 | 4/8/2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN… | |
| Analizada | Crítica (9.8) | 0.68% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 22/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access… | |
| Analizada | Media (6.7) | 0.19% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 1.4% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root… | |
| Analizada | Alta (7.2) | 1.2% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 0.42% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (7.2) | 0.44% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 1.2% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (8.8) | 0.77% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this… | |
| Analizada | Alta (7.2) | 1.5% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker with remote access… | |
| Modificada | Media (6.7) | 0.25% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A… | |
| Modificada | Media (6.7) | 0.62% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high… | |
| Modificada | Media (6.7) | 0.57% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection')… | |
| Analizada | Media (6.7) | 0.52% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with local access could… | |
| Analizada | Alta (8.8) | 0.22% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low… | |
| Analizada | Alta (7.2) | 1.1% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could… | |
| Analizada | Alta (8.4) | 0.16% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker with local access… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — | |
| Aplazada | Crítica (9.4) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — | |
| Aplazada | Alta (7.3) | 0.36% | — | Novakon P SeriesAI | 23/9/2025 | 30/9/2026 | — | |
| Aplazada | Alta (8.6) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9). | |
| Aplazada | Crítica (10) | 1.1% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | — | |
| Aplazada | Crítica (10) | 93% | — | Linksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+2 | 24/6/2025 | 22/7/2026 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Rockwellautomation 1756-en2t Series A FirmwareRockwellautomation 1756-en2t Series B FirmwareRockwellautomation 1756-en2t Series C FirmwareRockwellautomation 1756-en2t Series D Firmware+29 | 20/9/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to… |