Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Netgear Fvs318g FirmwareNetgear Fvs318n FirmwareNetgear Fvs336g FirmwareNetgear Srx5308 Firmware28/4/202017/6/2026
Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before 2017-02-10, FVS318N before 2017-02-10, and FVS318Gv2 before 2017-02-10.
ModificadaMedia (6.5)2.5%—Netgear Fvs336gv3 FirmwareNetgear Srx5308 FirmwareNetgear Fvs318gv2 FirmwareNetgear Fvs318n Firmware3/1/201717/6/2026
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
ModificadaAlta (7.5)2.2%—Netgear Prosafe Fvs318n28/4/201216/6/2026
The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.
ModificadaMedia (4.3)1.4%—Netgear Fvs31817/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.
ModificadaAlta (7.5)2.0%—Netgear Fvs31817/1/200516/6/2026
NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.
ModificadaMedia (5)1.6%—Netgear Fvs3186/12/200416/6/2026
Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.
ModificadaBaja (2.1)0.63%—Netgear Fvs31831/12/200216/6/2026
NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information.