Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—Cente Middleware TCP IP Network SeriesAI14/2/202517/6/2026
Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.
AplazadaAlta (7.6)0.34%—130 8005 TCP IP GatewayAI13/2/202517/6/2026
A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform changes over resources…
AplazadaMedia (5.7)0.38%—130 8005 TCP IP GatewayAI13/2/202517/6/2026
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to information leakage scenarios. An attacker…
AplazadaAlta (7.6)0.40%—130 8005 TCP IP GatewayAI13/2/202517/6/2026
A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid authentication tokens…
AnalizadaMedia (5.3)0.76%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3Nxtech Cente Tcp/ipv4+215/4/202417/6/2026
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
ModificadaMedia (5.9)0.81%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within…
ModificadaMedia (5.9)0.81%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within…
ModificadaCrítica (9.1)1.1%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this…
ModificadaCrítica (9.8)1.1%—Silabs Uc/tcp-ip10/10/202317/6/2026
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
ModificadaMedia (6.1)0.72%—Broadcom Netmaster File Transfer ManagementBroadcom Netmaster Network Management FOR Tcp/ip18/1/202217/6/2026
NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.
ModificadaAlta (7.5)0.97%—Unisys Clearpath MCP Tcp/ip Networking Services12/1/202217/6/2026
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
ModificadaCrítica (9.8)3.6%—Hcc-embedded Nichestack Tcp/ip18/8/202117/6/2026
The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the…
ModificadaAlta (7.5)2.3%—Hcc-embedded Nichestack Tcp/ip18/8/202117/6/2026
The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in function: dns_upcall(). The attack vector is: a specific DNS response packet. The code does not check whether the number of…
ModificadaAlta (7.5)1.3%—Hcc-embedded Nichestack Tcp/ip18/8/202117/6/2026
The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS response packet.
ModificadaCrítica (9.8)3.5%—Treck Tcp/ip22/12/202017/6/2026
A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.
ModificadaMedia (4.3)1.7%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
ModificadaMedia (5.3)3.3%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
ModificadaMedia (5.3)4.5%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.
ModificadaMedia (5.3)3.1%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
ModificadaMedia (5.3)11%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.
ModificadaMedia (5.3)3.6%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.
ModificadaMedia (4.3)1.9%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.
ModificadaMedia (6.3)2.0%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.
ModificadaMedia (6.3)2.0%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
ModificadaMedia (6.5)2.0%—Treck Tcp/ip17/6/202017/6/2026
The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.