Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.58% | — | Xiketor Layer3 SwitchesAI | 16/9/2026 | 16/9/2026 | XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host. | |
| Pendiente de análisis | Alta (8.7) | 0.77% | — | Hirschmann Hios Switch PlatformAI | 15/9/2026 | 24/9/2026 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform… | |
| Aplazada | Alta (7) | 0.25% | — | Nintendo SwitchAI | 10/9/2026 | 11/9/2026 | A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0. | |
| Aplazada | Crítica (9.6) | 0.41% | — | UI Edgemax EdgeswitchAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, and cycle_duration fields into small fixed-size buffers without proper… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a… | |
| Aplazada | Alta (8.8) | 0.55% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration,… | |
| Aplazada | Media (6.9) | 1.0% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on… | |
| Aplazada | Alta (8.6) | 1.8% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… |