Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Landwire Responsive Block ControlAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in landwire Responsive Block Control responsive-block-control allows DOM-Based XSS.This issue affects Responsive Block Control: from n/a through <= 1.3.0. | |
| Aplazada | Media (5.1) | 0.16% | — | Devolo Dlan 500 AV Wireless PlusAI | 24/12/2025 | 17/6/2026 | Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a… | |
| Aplazada | Alta (8.7) | 0.42% | — | Devolo Dlan 500 AV Wireless+AI | 24/12/2025 | 17/6/2026 | devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration… | |
| Analizada | Media (5.5) | 0.15% | — | Wireshark | 3/12/2025 | 17/6/2026 | MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service | |
| Analizada | Media (5.5) | 0.16% | — | Wireshark | 3/12/2025 | 17/6/2026 | HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service | |
| Analizada | Media (5.5) | 0.11% | — | Wireshark | 26/11/2025 | 17/6/2026 | BPv7 dissector crash in Wireshark 4.6.0 allows denial of service | |
| Analizada | Media (6.1) | 0.22% | 💥 PoC | Ruckuswireless Ruckus Unleashed | 25/11/2025 | 17/6/2026 | A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp. | |
| Analizada | Media (5.5) | 0.12% | — | Wireshark | 21/11/2025 | 17/6/2026 | Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (7) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (5.7) | 0.12% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Authorized adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur… | |
| Aplazada | Alta (7.5) | 0.31% | — | Italy Wireless Mini Router Wireless-n 300mAI | 30/10/2025 | 17/6/2026 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password. | |
| Aplazada | Alta (7.5) | 0.33% | — | Eachitaly Wireless-n 300mAI | 30/10/2025 | 17/6/2026 | Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request. | |
| Analizada | Media (6.5) | 0.43% | — | Processwire | 21/10/2025 | 17/6/2026 | ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service. | |
| Analizada | Media (5.5) | 0.12% | — | Wireshark | 10/10/2025 | 17/6/2026 | MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service | |
| Analizada | Media (5.4) | 0.31% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website. | |
| Analizada | Alta (7.3) | 0.39% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution. | |
| Analizada | Alta (7.3) | 0.29% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database. | |
| Aplazada | Media (5.1) | 0.14% | — | FrostwireAI | 2/10/2025 | 17/6/2026 | FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary… | |
| Aplazada | Media (6.5) | 0.21% | 💥 PoC | Eachitaly Wireless Mini RouterAI | 29/9/2025 | 17/6/2026 | Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands. | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Alta (8.8) | 0.18% | — | Megatek Azora Wireless Network ManagementAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the… |