Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Net-snmpAI | 11/9/2026 | 24/9/2026 | Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main… | |
| Aplazada | Crítica (9.3) | 1.3% | — | Voltronicpower Snmp WEB PROAI | 4/9/2026 | 10/9/2026 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive… | |
| Aplazada | Media (6.3) | 0.71% | — | Erlang OTPAIErlang SnmpAI | 1/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Snmp4j-agentAI | 15/6/2026 | 17/6/2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. | |
| Modificada | Alta (7.1) | 0.39% | — | Lolypop55 Html5 Snmp | 6/2/2026 | 17/6/2026 | html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted… | |
| Modificada | Media (5.1) | 0.21% | — | Lolypop55 Html5 Snmp | 6/2/2026 | 17/6/2026 | html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the… | |
| Aplazada | Alta (7.1) | 0.20% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Alta (8.4) | 0.27% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Alta (7.1) | 0.20% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Analizada | Crítica (9.8) | 42% | — | Net-snmpDebian Linux | 23/12/2025 | 17/6/2026 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2. | |
| Modificada | Media (4.3) | 0.82% | — | Cdpenergy Snmp WEB PRO Firmware | 9/12/2025 | 17/6/2026 | An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling… | |
| Aplazada | Media (6.9) | 0.11% | — | Microsoft WindowsAINet-snmpAI | 26/11/2025 | 17/6/2026 | CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges. | |
| Aplazada | Alta (7.8) | 0.17% | — | Hitachi JP1 Extensible Snmp AgentAIHitachi JOB Management Partner1 Extensible Snmp AgentAI | 2/7/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issue affects JP1/Extensible SNMP Agent for Windows: from 12-00 before 12-00-01,… | |
| Analizada | Alta (8.8) | 1.1% | — | Net-snmpDebian LinuxFedoraproject Fedora | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong… | |
| Analizada | Media (6.5) | 1.0% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.… | |
| Analizada | Media (5.3) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use… | |
| Analizada | Alta (8.8) | 1.3% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users… | |
| Analizada | Media (5.3) | 0.76% | — | Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3Nxtech Cente Tcp/ipv4+2 | 15/4/2024 | 17/6/2026 | Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device. | |
| Analizada | Media (5.3) | 0.54% | — | Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3 | 15/4/2024 | 17/6/2026 | Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet. | |
| Analizada | Alta (7.5) | 0.61% | — | Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3 | 15/4/2024 | 17/6/2026 | Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet. | |
| Modificada | Media (6.1) | 0.54% | — | Voltronicpower Snmp WEB PRO | 12/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver. | |
| Modificada | Crítica (9.8) | 1.1% | — | Voltronicpower Snmp WEB PRO | 12/9/2023 | 17/6/2026 | An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request. | |
| Modificada | Crítica (9.8) | 1.1% | — | Voltronicpower Snmp WEB PRO | 12/7/2023 | 17/6/2026 | The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances… |