Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.1)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the…
RecibidaAlta (7.1)——Arista Wi-fi Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is…
RecibidaCrítica (9)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access…
RecibidaAlta (7.7)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
RecibidaCrítica (9.4)——Arista Wi-fi Access PointsAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition…
Pendiente de análisisMedia (6.3)0.50%—IBM I Access FamilyAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.
Pendiente de análisisMedia (6.3)0.27%—IBM I Access FamilyAIIBM I Access Client SolutionsAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.
Pendiente de análisisMedia (6.3)0.27%—IBM I Access FamilyAIIBM I Access Client SolutionsAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
AplazadaCrítica (9.9)0.47%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AnalizadaAlta (7.8)0.17%—IBM I Access Client Solutions13/8/202617/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
AnalizadaAlta (7.8)0.21%—IBM I Access Client Solutions12/8/202618/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (7.1)0.11%—IBM I Access Client Solutions12/8/202618/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
AnalizadaCrítica (9.6)0.17%—IBM I Access Client Solutions12/8/202618/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
AnalizadaAlta (8.8)0.50%—IBM I Access Client Solutions12/8/202618/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
AnalizadaAlta (7.8)0.20%—IBM I Access Client Solutions12/8/202618/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
AnalizadaAlta (8.6)0.56%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
AnalizadaCrítica (9.1)0.52%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
AnalizadaCrítica (9.9)1.6%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AnalizadaAlta (8.8)0.81%—IBM I Access Client Solutions1/6/202626/8/2026
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
AplazadaMedia (5.1)0.20%—Zucchetti Axess Cloki Access ControlAI23/12/202517/6/2026
Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users…
AnalizadaCrítica (10)41%💥 ExploitUI Unifi Access31/10/202517/6/2026
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi…
AplazadaCrítica (9.8)1.2%—UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+24/8/202517/6/2026
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro…
Orbitaley — Vulnerabilidades