Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1800 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.19%—Landwire Responsive Block ControlAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in landwire Responsive Block Control responsive-block-control allows DOM-Based XSS.This issue affects Responsive Block Control: from n/a through <= 1.3.0.
AplazadaMedia (5.1)0.16%—Devolo Dlan 500 AV Wireless PlusAI24/12/202517/6/2026
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a…
AplazadaAlta (8.7)0.42%—Devolo Dlan 500 AV Wireless+AI24/12/202517/6/2026
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration…
AnalizadaMedia (5.5)0.15%—Wireshark3/12/202517/6/2026
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
AnalizadaMedia (5.5)0.16%—Wireshark3/12/202517/6/2026
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
AnalizadaMedia (5.5)0.11%—Wireshark26/11/202517/6/2026
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
AnalizadaMedia (6.1)0.22%💥 PoCRuckuswireless Ruckus Unleashed25/11/202517/6/2026
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
AnalizadaMedia (5.5)0.12%—Wireshark21/11/202517/6/2026
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (7)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaMedia (5.7)0.12%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Authorized adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur…
AplazadaAlta (7.5)0.31%—Italy Wireless Mini Router Wireless-n 300mAI30/10/202517/6/2026
Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.
AplazadaAlta (7.5)0.33%—Eachitaly Wireless-n 300mAI30/10/202517/6/2026
Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.
AnalizadaMedia (6.5)0.43%—Processwire21/10/202517/6/2026
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
AnalizadaMedia (5.5)0.12%—Wireshark10/10/202517/6/2026
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
AnalizadaMedia (5.4)0.31%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.
AnalizadaAlta (7.3)0.39%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.
AnalizadaAlta (7.3)0.29%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.
AplazadaMedia (5.1)0.14%—FrostwireAI2/10/202517/6/2026
FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary…
AplazadaMedia (6.5)0.21%💥 PoCEachitaly Wireless Mini RouterAI29/9/202517/6/2026
Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.
AplazadaMedia (4.3)0.12%—Cisco Wireless Access Point SoftwareAI24/9/202525/9/2026
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action…
AplazadaAlta (8.8)0.18%—Megatek Azora Wireless Network ManagementAI16/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the…
Orbitaley — Vulnerabilidades