Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.55% | — | Shenzhen Tenda Technology W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Shenzhen Tenda Technology W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W15eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.41% | — | Tenda W15e Firmware | 9/3/2026 | 17/6/2026 | An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote… | |
| Analizada | Media (6) | 0.92% | — | HP W3z72e FirmwareHP W3z72f FirmwareHP W3z72g FirmwareHP W3z72h Firmware+69 | 25/7/2025 | 17/6/2026 | Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information. | |
| Analizada | Alta (8.8) | 1.8% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. Affected is the function guestWifiRuleRefresh. The manipulation of the argument qosGuestDownstream leads to stack-based buffer overflow. It is possible to launch the attack remotely. VDB-261870 is the identifier assigned to this… | |
| Analizada | Alta (8.8) | 1.8% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. This issue affects the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument manualTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 1.8% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. This vulnerability affects the function formSetStaticRoute of the file /goform/setStaticRoute. The manipulation of the argument staticRouteIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. This affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the argument remoteIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda W15E 15.11.0.14. Affected by this issue is the function formSetPortMapping of the file /goform/SetPortMapping. The manipulation of the argument portMappingServer/portMappingProtocol/portMappingWan/porMappingtInternal/portMappingExternal leads… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in Tenda W15E 15.11.0.14. Affected by this vulnerability is the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Tenda W15E 15.11.0.14. Affected is the function formQOSRuleDel. The manipulation of the argument qosIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-261864. NOTE: The vendor was… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14. It has been rated as critical. This issue affects the function formIPMacBindModify of the file /goform/modifyIpMacBind. The manipulation of the argument IPMacBindRuleId/IPMacBindRuleIp/IPMacBindRuleMac/IPMacBindRuleRemark leads to stack-based buffer overflow. The… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. The manipulation of the argument IPMacBindIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. This affects the function formIPMacBindAdd of the file /goform/addIpMacBind. The manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this issue is the function formDelPortMapping of the file /goform/DelPortMapping. The manipulation of the argument portMappingIndex leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this vulnerability is the function formDelDhcpRule of the file /goform/DelDhcpRule. The manipulation of the argument delDhcpIndex leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has… | |
| Analizada | Alta (8.8) | 1.7% | — | Tenda W15e Firmware | 24/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. Affected is the function formAddDnsForward of the file /goform/AddDnsForward. The manipulation of the argument DnsForwardRule leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… |