Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.2) | 0.51% | — | Repeater Fields FOR Gravity FormsAI | 9/9/2026 | 9/9/2026 | The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.9) | 3.6% | — | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may… | |
| Aplazada | Media (6.4) | 0.32% | — | Sympl Repeater FOR ACF AND ElementorAI | 8/7/2026 | 8/7/2026 | The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to… | |
| Aplazada | Crítica (9.3) | 2.9% | — | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 1/7/2026 | 6/7/2026 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append… | |
| Aplazada | Media (5.3) | 0.29% | — | Coding Panda Panda Pods Repeater FieldAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12. | |
| Aplazada | Crítica (9.4) | 87% | — | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 7/8/2025 | 17/6/2026 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points,… | |
| Aplazada | Media (5.7) | 0.60% | — | Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI | 10/9/2024 | 17/6/2026 | OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed. | |
| Modificada | Alta (7.5) | 14% | — | Aigital Wireless-n Repeater Mini Router Firmware | 2/5/2023 | 17/6/2026 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user. | |
| Modificada | Media (5.4) | 29% | — | Aigital Wireless-n Repeater Mini Router Firmware | 28/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup. | |
| Modificada | Crítica (9.8) | 2.2% | — | Aigital Wireless-n Repeater Mini Router Firmware | 26/4/2023 | 9/7/2026 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | |
| Modificada | Media (4.8) | 0.39% | — | Content-repeater Project Content-repeater | 18/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions. | |
| Modificada | Media (5.4) | 0.84% | — | Panda Pods Repeater Field Project Panda Pods Repeater Field | 30/1/2023 | 17/6/2026 | The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission. | |
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml. | |
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini. | |
| Modificada | Media (6.3) | 0.63% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml. | |
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt. | |
| Modificada | Alta (8) | 0.87% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml. | |
| Modificada | Alta (7.5) | 4.2% | — | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP. | |
| Modificada | Alta (7.5) | 2.0% | — | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required. | |
| Modificada | Media (6.1) | 0.82% | — | Acexy Wireless-n Wifi Repeater Project Acexy Wireless-n Wifi Repeater Firmware | 18/3/2021 | 17/6/2026 | Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section). | |
| Modificada | Crítica (9.8) | 28% | — | Alleghenycreative Openrepeater | 19/2/2021 | 17/6/2026 | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. | |
| Modificada | Media (5) | 0.46% | — | Mirion Technologies DMC 3000 FirmwareMirion Technologies Ipam Transmitter F/dmc 2000 FirmwareMirion Technologies Telepole II FirmwareMirion Technologies Rds-31 ITX Firmware+3 | 20/9/2017 | 17/6/2026 | A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II,… | |
| Modificada | Crítica (9.8) | 1.4% | — | Twsz Wifi Repeater Firmware | 20/9/2017 | 17/6/2026 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the file system; or 3. Execute any code that attacker desires (malicious or not). | |
| Modificada | Crítica (9.8) | 1.4% | — | Twsz Wifi Repeater Firmware | 20/9/2017 | 17/6/2026 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the telnet and will infect the device with… |