Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
RecibidaAlta (8.8)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked…
RecibidaAlta (7.4)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked…
RecibidaAlta (8.2)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked…
RecibidaAlta (7.5)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked…
RecibidaCrítica (9.6)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked…
RecibidaAlta (8.8)——Cisco Meraki Campus GatewaysAICisco Meraki MG Cellular GatewaysAICisco Meraki MR Wireless Access PointsAICisco Meraki MS Series SwitchesAI+37/10/20267/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked…
Pendiente de análisisMedia (6.2)0.13%—Elastic EndpointAI6/10/20267/10/2026
Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can…
Pendiente de análisisAlta (7.1)0.28%—Arista WI FI Access PointAI6/10/20267/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the…
Pendiente de análisisAlta (7.1)0.28%—Arista Wi-fi Access PointAI6/10/20267/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is…
Pendiente de análisisCrítica (9)0.23%—Arista WI FI Access PointAI6/10/20267/10/2026
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access…
Pendiente de análisisAlta (7.7)0.24%—Arista WI FI Access PointAI6/10/20267/10/2026
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
Pendiente de análisisBaja (2.3)0.19%—Arista Access PointAI6/10/20267/10/2026
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code…
Pendiente de análisisAlta (8.7)0.31%—Arista Access PointAI6/10/20267/10/2026
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless…
Pendiente de análisisCrítica (9.4)0.25%—Arista Wi-fi Access PointsAI6/10/20267/10/2026
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition…
AplazadaMedia (6.5)0.26%—WappointmentAI6/10/20266/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
AplazadaCrítica (9.3)0.38%—Woocommerce AppointmentsAI6/10/20266/10/2026
Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.
AplazadaBaja (2.1)0.20%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote…
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be…
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible…
AplazadaMedia (6.5)0.13%—Themepoints Logo ShowcaseAI5/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4.
AplazadaCrítica (9.1)0.88%—Vikappointments Services Booking CalendarAI3/10/20266/10/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…