Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.63% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.24% | — | Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 17/6/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Aplazada | Media (5.1) | 0.29% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations. | |
| Aplazada | Media (5.1) | 0.33% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken. | |
| Aplazada | Media (4.8) | 0.25% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser. | |
| Aplazada | Crítica (9.3) | 2.3% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed. | |
| Aplazada | Media (6.9) | 0.12% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file. | |
| Aplazada | Media (5.1) | 0.15% | — | Elecom Wireless LANAI | 3/2/2026 | 17/6/2026 | Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed. | |
| Aplazada | Alta (8.5) | 0.15% | — | Realtek Wireless LAN UtilityAI | 21/1/2026 | 17/6/2026 | Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or… | |
| Aplazada | Alta (7.4) | 0.25% | — | Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI | 7/5/2025 | 17/6/2026 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Aplazada | Media (5.7) | 0.60% | — | Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI | 10/9/2024 | 17/6/2026 | OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed. | |
| Aplazada | Media (6.8) | 0.85% | — | Elecom Wireless LAN RouterAI | 1/8/2024 | 17/6/2026 | OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command. | |
| Aplazada | Media (6.8) | 0.36% | — | Elecom Wireless LAN RouterAI | 1/8/2024 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution. | |
| Aplazada | Media (4.3) | 0.25% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request. | |
| Aplazada | Alta (7.1) | 0.69% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. | |
| Analizada | Alta (7.4) | 0.29% | — | Cisco Wireless LAN Controller SoftwareCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed… | |
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Modificada | Media (4.7) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware | 27/9/2023 | 17/6/2026 | This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A… |