Vulnerabilities
Summary — last 7 days
New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
104 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.5) | 2.0% | — | Mikrotik Routeros | 7/7/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet. | |
| Modified | Medium (6.5) | 1.6% | — | Mikrotik Routeros | 7/7/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 1.5% | — | Mikrotik Routeros | 7/7/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access. | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 7/7/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. | |
| Modified | Medium (6.5) | 2.3% | — | Mikrotik Routeros | 7/7/2021 | 9/16/2026 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 2.5% | — | Mikrotik Routeros | 7/7/2021 | 9/16/2026 | Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet. | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 5/19/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 5/19/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error. | |
| Modified | Medium (6.5) | 2.7% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access. | |
| Modified | Medium (6.5) | 2.7% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access. | |
| Modified | Medium (6.5) | 3.1% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access. | |
| Modified | Medium (6.5) | 2.7% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 2.8% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access. | |
| Modified | Medium (6.5) | 3.2% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access. | |
| Modified | Medium (6.5) | 3.2% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 3.1% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet. | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 5/18/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error. | |
| Modified | Medium (6.5) | 1.7% | — | Mikrotik Routeros | 5/11/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access. | |
| Modified | Medium (6.5) | 2.1% | — | Mikrotik Routeros | 5/11/2021 | 6/17/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet. | |
| Modified | Medium (6.5) | 1.1% | — | Mikrotik Routeros | 5/3/2021 | 6/17/2026 | Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable. | |
| Modified | Medium (6.5) | 2.0% | — | Mikrotik Routeros | 5/3/2021 | 6/17/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable. | |
| Modified | High (8.1) | 4.5% | — | Mikrotik Routeros | 3/19/2021 | 6/17/2026 | MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work | |
| Modified | Medium (6.1) | 0.94% | — | Mikrotik Routeros | 1/4/2021 | 6/17/2026 | In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter. | |
| Modified | High (7.5) | 2.6% | — | Mikrotik Routeros | 10/7/2020 | 6/17/2026 | An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service. |