Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.4% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+48 | 24/2/2026 | 17/6/2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | |
| Analizada | Media (4.9) | 1.9% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+44 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.8% | — | Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.2% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 0.81% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service… | |
| Analizada | Alta (8.8) | 1.1% | — | Zyxel Dm4200-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+50 | 18/11/2025 | 17/6/2026 | A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | |
| Analizada | Alta (7.5) | 0.31% | — | Zyxel Lte3301-plus FirmwareZyxel Nr5103 FirmwareZyxel Nr5103e FirmwareZyxel Nr5309 Firmware+62 | 18/11/2025 | 17/6/2026 | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web… | |
| Analizada | Alta (7.2) | 1.1% | — | Zyxel Wx5610-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+37 | 11/3/2025 | 17/6/2026 | A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device. | |
| Analizada | Alta (7.5) | 0.52% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7480-m804 Firmware+59 | 3/12/2024 | 17/6/2026 | A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+38 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an… | |
| Analizada | Alta (7.5) | 0.66% | — | Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+46 | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Analizada | Media (5.5) | 0.14% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 Firmware+61 | 21/5/2024 | 17/6/2026 | The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. | |
| Modificada | Media (6.5) | 0.62% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. | |
| Modificada | Media (6.5) | 0.72% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.1% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+35 | 11/1/2023 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. | |
| Modificada | Media (6.1) | 1.1% | — | Lenovo Bladecenter Hs22 FirmwareLenovo Bladecenter Hs22v FirmwareLenovo Bladecenter HX5 FirmwareLenovo System X Idataplex Dx360 M2 Firmware+11 | 19/8/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the… | |
| Modificada | Media (6.8) | 2.0% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 14/10/2014 | 17/6/2026 | The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted… | |
| Modificada | Media (5.4) | 1.7% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2014 | 17/6/2026 | Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4. | |
| Modificada | Alta (7.8) | 3.4% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2014 | 17/6/2026 | Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a… | |
| Modificada | Alta (7.8) | 1.8% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2014 | 17/6/2026 | Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet. | |
| Modificada | Alta (7.1) | 2.3% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 15/1/2014 | 17/6/2026 | Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet. | |
| Modificada | Alta (7.8) | 3.6% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/1/2014 | 17/6/2026 | Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP… |