Vulnerabilities
Summary — last 7 days
New vulnerabilities2,676▼ 422 vs. last week
Critical / high1,295▼ 73 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)244▼ 274 vs. last week
192 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.3) | 0.24% | — | Netgear Cbr750 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 FirmwareNetgear Mr60 Firmware+31 | 6/9/2026 | 7/23/2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | |
| Analyzed | Medium (4.3) | 0.23% | — | Netgear Rbe970 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 FirmwareNetgear Rbr850 Firmware+9 | 6/9/2026 | 7/23/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analyzed | Medium (4.3) | 0.32% | — | Netgear Rbe370 FirmwareNetgear Rbe770 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 Firmware+10 | 6/9/2026 | 7/23/2026 | A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analyzed | Medium (6.1) | 0.37% | — | Netgear Cbr750 FirmwareNetgear Nbr750 FirmwareNetgear Rbe370 FirmwareNetgear Rbe371 Firmware+21 | 1/13/2026 | 6/17/2026 | An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin. | |
| Analyzed | Medium (4.8) | 1.2% | — | Netgear Rbr750 FirmwareNetgear Rbr840 FirmwareNetgear Rbr850 FirmwareNetgear Rbr860 Firmware+8 | 1/13/2026 | 6/17/2026 | An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default. | |
| Analyzed | Low (1.1) | 0.32% | — | Netgear Rbe971 FirmwareNetgear Rbe970 FirmwareNetgear Rbr750 FirmwareNetgear Rbr850 Firmware+6 | 1/13/2026 | 6/17/2026 | An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections. | |
| Analyzed | Medium (4.9) | 0.31% | — | Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+108 | 9/25/2025 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analyzed | High (8.8) | 0.27% | — | Gl-inet Mt6000 FirmwareGl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+17 | 10/24/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control. | |
| Analyzed | High (8.8) | 0.67% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 10/24/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path. | |
| Analyzed | High (8) | 0.49% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 10/24/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication… | |
| Analyzed | High (8) | 4.1% | — | Gl-inet Mt6000 FirmwareGl-inet B1300 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+17 | 10/24/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it. | |
| Analyzed | Medium (6.5) | 0.23% | — | Gl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 Firmware+17 | 10/24/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted. | |
| Modified | High (7.5) | 0.43% | — | Gl-inet Mt6000 FirmwareGl-inet X3000 FirmwareGl-inet Xe3000 FirmwareGl-inet A1300 Firmware+14 | 8/26/2024 | 6/17/2026 | A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square… | |
| Modified | Medium (5.3) | 0.18% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 8/6/2024 | 6/17/2026 | An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications… | |
| Modified | Critical (9.8) | 1.2% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 8/6/2024 | 6/17/2026 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint /cgi-bin/glc. This vulnerability allows… | |
| Modified | Critical (9.8) | 0.66% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 8/6/2024 | 6/17/2026 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the interface check_ovpn_client_config and… | |
| Modified | Critical (9.8) | 20% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 8/6/2024 | 6/17/2026 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to manipulate routers by passing malicious… | |
| Modified | Critical (9.8) | 14% | — | Gl-inet Mt6000 FirmwareGl-inet A1300 FirmwareGl-inet X300b FirmwareGl-inet Ax1800 Firmware+24 | 8/6/2024 | 6/17/2026 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability. | |
| Analyzed | High (7.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+89 | 4/3/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Analyzed | Low (3.3) | 0.17% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 3/13/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analyzed | Medium (6.3) | 0.11% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 3/13/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. | |
| Analyzed | High (8.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 3/13/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM. | |
| Analyzed | Low (3.3) | 0.20% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 3/13/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analyzed | High (8.4) | 0.20% | — | Dell Poweredge T360 FirmwareDell Poweredge R360 FirmwareDell Poweredge R650 FirmwareDell Poweredge R750 Firmware+82 | 3/13/2024 | 6/17/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | |
| Analyzed | High (7.5) | 24% | — | Gl-inet Mt6000 FirmwareGl-inet Xe3000 FirmwareGl-inet X3000 FirmwareGl-inet Mt3000 Firmware+22 | 2/27/2024 | 6/17/2026 | An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200… |