Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.65% | — | Openwrt Luci-app-advanced-rebootAI | 21/9/2026 | 24/9/2026 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in… | |
| Aplazada | Alta (8.8) | 0.49% | — | Openwrt Luci-app-adblock-fastAI | 21/9/2026 | 29/9/2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as… | |
| Aplazada | Alta (8.8) | 0.78% | — | Openwrt Luci-app-https-dns-proxyAI | 27/8/2026 | 1/9/2026 | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter | |
| Aplazada | Media (6.9) | 0.11% | — | Luci-lib-px5gAIOpenwrtAI | 22/8/2026 | 24/9/2026 | luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after… | |
| Aplazada | Alta (7.3) | 3.7% | — | Baicells Eg3661mAIOpenwrt LuciAI | 14/8/2026 | 18/8/2026 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Crítica (9.4) | 0.62% | — | Openwrt Luci-app-lxcAIOpenwrtAI | 13/8/2026 | 30/9/2026 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control… | |
| Aplazada | Crítica (9.4) | 0.62% | — | Luci-app-openvpnAI | 13/8/2026 | 30/9/2026 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system… | |
| Aplazada | Alta (8.7) | 0.44% | — | Openwrt LuciAIOpenwrt Luci-mod-system-mountsAI | 13/8/2026 | 30/9/2026 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default… | |
| Aplazada | Alta (8.8) | 0.17% | — | Lucid Vision Labs Arena SDKAI | 7/8/2026 | 26/8/2026 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency… | |
| Aplazada | Alta (8.7) | 3.3% | — | Openwrt Luci-app-dockermanAIOpenwrtAI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the… | |
| Aplazada | Alta (8.7) | 0.93% | — | Openwrt Luci-app-bmx7AI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the… | |
| Aplazada | Media (5.1) | 0.24% | — | Luci-app-adblock-fastAI | 2/8/2026 | 9/9/2026 | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin. | |
| Pendiente de análisis | Media (6.8) | 0.41% | — | Luci-app-https-dns-proxyAI | 1/8/2026 | 8/9/2026 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Ellucian Advance WEBAIEllucian Advance LegacyAI | 28/7/2026 | 9/9/2026 | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM… | |
| Aplazada | Alta (8.7) | 0.78% | — | Luci-app-banipAI | 13/7/2026 | 15/7/2026 | luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the… | |
| Pendiente de análisis | Crítica (9.4) | 1.3% | — | Openwrt LuciAI | 12/7/2026 | 14/7/2026 | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages. | |
| Aplazada | Alta (8.7) | 0.55% | — | Luci-app-upnpAIMiniupnpdAI | 12/7/2026 | 30/9/2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,… | |
| Aplazada | Alta (8.7) | 0.68% | — | Openwrt Luci-app-samba4AISambaAI | 12/7/2026 | 30/9/2026 | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command… | |
| Aplazada | Alta (7.7) | 0.80% | — | Openwrt Luci-app-travelmateAIOpenwrt TravelmateAI | 2/7/2026 | 28/8/2026 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only… | |
| Aplazada | Alta (8.7) | 2.7% | — | Openwrt Luci-proto-openvpnAI | 29/6/2026 | 14/7/2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject… | |
| Aplazada | Alta (7.7) | 2.3% | — | Luci-app-tailscale-communityAI | 29/6/2026 | 14/7/2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a… | |
| Aplazada | Media (5.1) | 0.34% | — | Ellucian Banner Self-serviceAI | 9/6/2026 | 23/7/2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding during DOM insertion.… | |
| Aplazada | Media (5.1) | 0.36% | — | Ellucian Banner Self-serviceAI | 9/6/2026 | 23/7/2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter… | |
| Aplazada | Media (5.3) | 1.1% | — | LuciAIGl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON-RPC Interface. Such manipulation leads to command injection. The attack may be performed from remote. Upgrading to version 4.8.1 is sufficient to… | |
| Aplazada | Alta (8.7) | 7.8% | — | Openwrt Luci-app-https-dns-proxyAI | 26/5/2026 | 24/7/2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the… |