Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 2.1% | — | Ruijie Rg-nbs5100-24gt4sfp FirmwareRuijie Rg-s1930 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to the module_update in file /usr/local/lua/dev_config/ace_sw.lua. | |
| Modificada | Alta (8.8) | 2.6% | — | Ruijie Rg-ew1200 FirmwareRuijie Rg-ew1200g PRO FirmwareRuijie Rg-ew1200r FirmwareRuijie Rg-ew1300g Firmware+92 | 17/8/2023 | 17/6/2026 | A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers… | |
| Modificada | Alta (8.1) | 0.38% | — | Huawei Cd10-10 FirmwareHuawei Cd16-10 FirmwareHuawei Cd17-10 FirmwareHuawei Cd18-10 Firmware+18 | 29/11/2019 | 17/6/2026 | Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories. | |
| Modificada | Alta (7.8) | 0.22% | — | Huawei Cd10-10 FirmwareHuawei Cd16-10 FirmwareHuawei Cd17-10 FirmwareHuawei Cd18-10 Firmware+18 | 29/11/2019 | 17/6/2026 | Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs, an attacker can exploit this vulnerability to execute uploaded malicious files and escalate privilege. | |
| Modificada | Alta (7.5) | 0.94% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack. | |
| Modificada | Alta (10) | 1.7% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers… | |
| Modificada | Alta (9.3) | 2.3% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Media (4.3) | 1.6% | — | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter. | |
| Modificada | Media (6.5) | 5.1% | — | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet… |