Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.24%—Repeater Fields FOR Elementor FormsAI25/9/202625/9/2026
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (7.2)0.51%—Repeater Fields FOR Gravity FormsAI9/9/20269/9/2026
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.9)3.6%—Shenzhen Aitemi M300 Wi-fi RepeaterAI9/8/202612/8/2026
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may…
AplazadaMedia (6.4)0.32%—Sympl Repeater FOR ACF AND ElementorAI8/7/20268/7/2026
The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to…
AplazadaCrítica (9.3)2.9%—Shenzhen Aitemi M300 Wi-fi RepeaterAI1/7/20266/7/2026
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append…
AplazadaMedia (5.3)0.29%—Coding Panda Panda Pods Repeater FieldAI8/4/202620/7/2026
Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12.
AplazadaCrítica (9.4)87%—Shenzhen Aitemi M300 Wi-fi RepeaterAI7/8/202517/6/2026
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points,…
AplazadaMedia (5.7)0.60%—Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI10/9/202417/6/2026
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
ModificadaAlta (7.5)14%—Aigital Wireless-n Repeater Mini Router Firmware2/5/202317/6/2026
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.
ModificadaMedia (5.4)29%—Aigital Wireless-n Repeater Mini Router Firmware28/4/202317/6/2026
A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup.
ModificadaCrítica (9.8)2.2%—Aigital Wireless-n Repeater Mini Router Firmware26/4/20239/7/2026
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
ModificadaMedia (4.8)0.39%—Content-repeater Project Content-repeater18/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.
ModificadaMedia (5.4)0.84%—Panda Pods Repeater Field Project Panda Pods Repeater Field30/1/202317/6/2026
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.
ModificadaMedia (6.3)0.63%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.
ModificadaAlta (8)0.87%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml.
ModificadaAlta (7.5)4.2%—Acexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
ModificadaAlta (7.5)2.0%—Acexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.
ModificadaMedia (6.1)0.82%—Acexy Wireless-n Wifi Repeater Project Acexy Wireless-n Wifi Repeater Firmware18/3/202117/6/2026
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).
ModificadaCrítica (9.8)28%—Alleghenycreative Openrepeater19/2/202117/6/2026
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
ModificadaMedia (5)0.46%—Mirion Technologies DMC 3000 FirmwareMirion Technologies Ipam Transmitter F/dmc 2000 FirmwareMirion Technologies Telepole II FirmwareMirion Technologies Rds-31 ITX Firmware+320/9/201717/6/2026
A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II,…
ModificadaCrítica (9.8)1.4%—Twsz Wifi Repeater Firmware20/9/201717/6/2026
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the file system; or 3. Execute any code that attacker desires (malicious or not).
ModificadaCrítica (9.8)1.4%—Twsz Wifi Repeater Firmware20/9/201717/6/2026
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the telnet and will infect the device with…