Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.49%—Net-snmpAI11/9/202624/9/2026
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main…
AplazadaCrítica (9.3)1.3%—Voltronicpower Snmp WEB PROAI4/9/202610/9/2026
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive…
AplazadaMedia (6.3)0.71%—Erlang OTPAIErlang SnmpAI1/9/20268/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2…
AplazadaCrítica (9.8)0.75%—Snmp4j-agentAI15/6/202617/6/2026
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
ModificadaAlta (7.1)0.39%—Lolypop55 Html5 Snmp6/2/202617/6/2026
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted…
ModificadaMedia (5.1)0.21%—Lolypop55 Html5 Snmp6/2/202617/6/2026
html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the…
AplazadaAlta (7.1)0.20%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AplazadaAlta (8.4)0.27%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AplazadaAlta (7.1)0.20%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AnalizadaCrítica (9.8)42%—Net-snmpDebian Linux23/12/202517/6/2026
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
ModificadaMedia (4.3)0.82%—Cdpenergy Snmp WEB PRO Firmware9/12/202517/6/2026
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling…
AplazadaMedia (6.9)0.11%—Microsoft WindowsAINet-snmpAI26/11/202517/6/2026
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.
AplazadaAlta (7.8)0.17%—Hitachi JP1 Extensible Snmp AgentAIHitachi JOB Management Partner1 Extensible Snmp AgentAI2/7/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issue affects JP1/Extensible SNMP Agent for Windows: from 12-00 before 12-00-01,…
AnalizadaAlta (8.8)1.1%—Net-snmpDebian LinuxFedoraproject Fedora16/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and…
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3…
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong…
AnalizadaMedia (6.5)1.0%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.…
AnalizadaMedia (5.3)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use…
AnalizadaAlta (8.8)1.3%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users…
AnalizadaMedia (5.3)0.76%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3Nxtech Cente Tcp/ipv4+215/4/202417/6/2026
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
AnalizadaMedia (5.3)0.54%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv315/4/202417/6/2026
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
AnalizadaAlta (7.5)0.61%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv315/4/202417/6/2026
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
ModificadaMedia (6.1)0.54%—Voltronicpower Snmp WEB PRO12/12/202317/6/2026
Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver.
ModificadaCrítica (9.8)1.1%—Voltronicpower Snmp WEB PRO12/9/202317/6/2026
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.
ModificadaCrítica (9.8)1.1%—Voltronicpower Snmp WEB PRO12/7/202317/6/2026
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances…