Vulnerabilities
Summary — last 7 days
New vulnerabilities2,768▼ 449 vs. last week
Critical / high1,325▼ 128 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)268▼ 240 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 1.2% | — | ZTE Zxv10 W908 Firmware | 12/1/2020 | 6/17/2026 | A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20. |