Vulnerabilities

Summary — last 7 days

New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

104 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.5)2.0%—Mikrotik Routeros7/7/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
ModifiedMedium (6.5)1.6%—Mikrotik Routeros7/7/20216/17/2026
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)1.5%—Mikrotik Routeros7/7/20216/17/2026
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
ModifiedMedium (6.5)2.1%—Mikrotik Routeros7/7/20216/17/2026
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
ModifiedMedium (6.5)2.3%—Mikrotik Routeros7/7/20219/16/2026
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)2.5%—Mikrotik Routeros7/7/20219/16/2026
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
ModifiedMedium (6.5)2.1%—Mikrotik Routeros5/19/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)2.1%—Mikrotik Routeros5/19/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.
ModifiedMedium (6.5)2.7%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
ModifiedMedium (6.5)2.7%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
ModifiedMedium (6.5)3.1%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
ModifiedMedium (6.5)2.7%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)2.8%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
ModifiedMedium (6.5)3.2%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
ModifiedMedium (6.5)3.2%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)3.1%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
ModifiedMedium (6.5)2.1%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
ModifiedMedium (6.5)2.1%—Mikrotik Routeros5/18/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.
ModifiedMedium (6.5)1.7%—Mikrotik Routeros5/11/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
ModifiedMedium (6.5)2.1%—Mikrotik Routeros5/11/20216/17/2026
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.
ModifiedMedium (6.5)1.1%—Mikrotik Routeros5/3/20216/17/2026
Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
ModifiedMedium (6.5)2.0%—Mikrotik Routeros5/3/20216/17/2026
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
ModifiedHigh (8.1)4.5%—Mikrotik Routeros3/19/20216/17/2026
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
ModifiedMedium (6.1)0.94%—Mikrotik Routeros1/4/20216/17/2026
In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
ModifiedHigh (7.5)2.6%—Mikrotik Routeros10/7/20206/17/2026
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.