Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Cente Middleware TCP IP Network SeriesAI | 14/2/2025 | 17/6/2026 | Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed. | |
| Aplazada | Alta (7.6) | 0.34% | — | 130 8005 TCP IP GatewayAI | 13/2/2025 | 17/6/2026 | A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform changes over resources… | |
| Aplazada | Media (5.7) | 0.38% | — | 130 8005 TCP IP GatewayAI | 13/2/2025 | 17/6/2026 | A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to information leakage scenarios. An attacker… | |
| Aplazada | Alta (7.6) | 0.40% | — | 130 8005 TCP IP GatewayAI | 13/2/2025 | 17/6/2026 | A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid authentication tokens… | |
| Analizada | Media (5.3) | 0.76% | — | Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3Nxtech Cente Tcp/ipv4+2 | 15/4/2024 | 17/6/2026 | Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device. | |
| Modificada | Media (5.9) | 0.81% | — | Weston-embedded Uc-tcp-ip | 20/2/2024 | 17/6/2026 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within… | |
| Modificada | Media (5.9) | 0.81% | — | Weston-embedded Uc-tcp-ip | 20/2/2024 | 17/6/2026 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within… | |
| Modificada | Crítica (9.1) | 1.1% | — | Weston-embedded Uc-tcp-ip | 20/2/2024 | 17/6/2026 | A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this… | |
| Modificada | Crítica (9.8) | 1.1% | — | Silabs Uc/tcp-ip | 10/10/2023 | 17/6/2026 | In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random. | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Netmaster File Transfer ManagementBroadcom Netmaster Network Management FOR Tcp/ip | 18/1/2022 | 17/6/2026 | NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine. | |
| Modificada | Alta (7.5) | 0.97% | — | Unisys Clearpath MCP Tcp/ip Networking Services | 12/1/2022 | 17/6/2026 | Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop. | |
| Modificada | Crítica (9.8) | 3.6% | — | Hcc-embedded Nichestack Tcp/ip | 18/8/2021 | 17/6/2026 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the… | |
| Modificada | Alta (7.5) | 2.3% | — | Hcc-embedded Nichestack Tcp/ip | 18/8/2021 | 17/6/2026 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in function: dns_upcall(). The attack vector is: a specific DNS response packet. The code does not check whether the number of… | |
| Modificada | Alta (7.5) | 1.3% | — | Hcc-embedded Nichestack Tcp/ip | 18/8/2021 | 17/6/2026 | The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS response packet. | |
| Modificada | Crítica (9.8) | 3.5% | — | Treck Tcp/ip | 22/12/2020 | 17/6/2026 | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code. | |
| Modificada | Media (4.3) | 1.7% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read. | |
| Modificada | Media (5.3) | 3.3% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | |
| Modificada | Media (5.3) | 4.5% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read. | |
| Modificada | Media (5.3) | 3.1% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control. | |
| Modificada | Media (5.3) | 11% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read. | |
| Modificada | Media (5.3) | 3.6% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow. | |
| Modificada | Media (4.3) | 1.9% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP. | |
| Modificada | Media (6.3) | 2.0% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP. | |
| Modificada | Media (6.3) | 2.0% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. | |
| Modificada | Media (6.5) | 2.0% | — | Treck Tcp/ip | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read. |