Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.68% | — | Tp-link Tl-sg108e Firmware | 27/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of the argument username/password leads to use of get request method with sensitive… | |
| Aplazada | Media (6.9) | 0.42% | — | Tp-link Tl-sg108eAI | 27/1/2025 | 17/6/2026 | A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to clickjacking. The attack may be initiated remotely. Upgrading to version 1.0.0 Build 20250124 Rel. 54920(Beta) is able to address this… | |
| Modificada | Media (6.5) | 0.72% | — | Tp-link Tl-sg108e Firmware | 20/12/2017 | 17/6/2026 | Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition. | |
| Modificada | Media (6.8) | 2.0% | — | Tp-link Tl-sg108e Firmware | 20/12/2017 | 17/6/2026 | Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies… | |
| Modificada | Media (5.4) | 0.59% | — | Tp-link Tl-sg108e Firmware | 20/12/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter. | |
| Modificada | Media (5.3) | 1.9% | — | Tp-link Tl-sg108e Firmware | 23/4/2017 | 17/6/2026 | On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. | |
| Modificada | Alta (7.5) | 1.1% | — | Tp-link Tl-sg108e Firmware | 23/4/2017 | 17/6/2026 | On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. | |
| Modificada | Crítica (9.8) | 0.90% | — | Tp-link Tl-sg108e Firmware | 23/4/2017 | 17/6/2026 | On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. | |
| Modificada | Crítica (9.8) | 1.8% | — | Tp-link Tl-sg108e Firmware | 23/4/2017 | 17/6/2026 | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tp-link Tl-sg108e Firmware | 23/4/2017 | 17/6/2026 | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |