Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 23% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header. | |
| Modificada | Media (6.1) | 0.69% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via the "username" cookie. | |
| Modificada | Media (6.5) | 1.3% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory contents via the "path" parameter. | |
| Modificada | Alta (8.8) | 0.99% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "method" parameter. | |
| Modificada | Alta (7.2) | 2.8% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the adminUsername and adminPassword parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensitive device information via an unauthenticated POST request. | |
| Modificada | Alta (7.2) | 2.8% | — | Buffalo Ts5600d1206 Firmware | 26/11/2018 | 17/6/2026 | System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" parameter. | |
| Modificada | Baja (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 1/4/2015 | 17/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modificada | Alta (7.5) | 0.94% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack. | |
| Modificada | Alta (10) | 1.7% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers… | |
| Modificada | Alta (9.3) | 2.3% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI. |