Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.13%—Wireshark29/9/20266/10/2026
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
AnalizadaMedia (5.5)0.13%—Wireshark29/9/20266/10/2026
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
AnalizadaMedia (5.5)0.13%—Wireshark29/9/20266/10/2026
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
AnalizadaMedia (5.5)0.12%—Wireshark29/9/20266/10/2026
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.15%—WiresharkAI29/9/202629/9/2026
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (4.7)0.13%—WiresharkAI29/9/202629/9/2026
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.16%—WiresharkAI29/9/202629/9/2026
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
En análisisAlta (8.1)0.39%—WiresharkAI29/9/202629/9/2026
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisMedia (5.5)0.14%—Wireshark SharkdAI29/9/202629/9/2026
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
En análisisAlta (8.1)0.36%—WiresharkAI29/9/202629/9/2026
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisAlta (7.5)0.58%—WireAI23/9/202630/9/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the…
AplazadaAlta (7.8)0.19%—Crosswire XiphosAI21/9/202622/9/2026
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
AplazadaMedia (4.3)0.36%—Wireguard Wg-portalAI17/9/202624/9/2026
WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every…
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisAlta (7.5)0.82%—Square WireAI16/9/202630/9/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin,…
AplazadaAlta (8.6)0.63%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
AplazadaMedia (4.8)0.24%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)1.9%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (4.8)0.24%—Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (7.5)0.50%—Signalwire LibksAI11/9/202630/9/2026
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."…