Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.88% | — | Sophos AP6 Series Wireless Access PointAI | 9/9/2025 | 17/6/2026 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7). | |
| Analizada | Alta (7.5) | 0.21% | — | Wireshark | 3/9/2025 | 25/9/2026 | SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service | |
| Aplazada | Alta (7.1) | 0.21% | — | Intel Proset Wireless Wifi SoftwareAI | 12/8/2025 | 17/6/2026 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.110.0.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (6.4) | 0.24% | — | FleetwireAI | 23/7/2025 | 17/6/2026 | The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetwire_list shortcode in all versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.2) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format… | |
| Analizada | Crítica (9.1) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute… | |
| Analizada | Crítica (9.8) | 1.3% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted… | |
| Analizada | Crítica (9.8) | 1.00% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated… | |
| Analizada | Media (6.3) | 0.37% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same… | |
| Analizada | Media (5.3) | 0.53% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable… | |
| Analizada | Crítica (9.1) | 0.83% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary… | |
| Analizada | Alta (8.8) | 0.51% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the… | |
| Analizada | Crítica (9.2) | 97% | ⚠ Explotación activa💥 Exploit | Laravel Livewire | 17/7/2025 | 17/6/2026 | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3… | |
| Aplazada | Alta (8.2) | 0.52% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in incorrect handling of packets leading to remote code… | |
| Aplazada | Crítica (9.4) | 0.76% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in a failure during subtraction allowing remote code… | |
| Aplazada | Media (6.5) | 0.25% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect… | |
| Aplazada | Alta (8.6) | 0.47% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code… | |
| Modificada | Media (6.5) | 0.29% | — | Jenkins Kryptowire | 9/7/2025 | 17/6/2026 | Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system. | |
| Aplazada | Media (4.1) | 0.17% | — | Wire IOSAI | 3/7/2025 | 17/6/2026 | wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created and managed by the application itself were not affected, especially not the logs… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Crítica (9.3) | 1.7% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Alta (7.2) | 1.4% | — | Hikvision Wireless Access PointAI | 13/6/2025 | 17/6/2026 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Analizada | Media (6.5) | 0.31% | — | Wireshark | 4/6/2025 | 17/6/2026 | Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file | |
| Analizada | Media (5.5) | 0.10% | — | Wire-webapp | 22/5/2025 | 17/6/2026 | wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the… | |
| Aplazada | Media (5.6) | 0.14% | — | Wire-webappAI | 22/5/2025 | 17/6/2026 | wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user… |