Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.2%—Emerson Controlwave Micro Firmware7/3/201817/6/2026
A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based buffer overflow vulnerability caused by sending crafted packets on Port 20547 could force the PLC…
ModificadaAlta (8.8)5.0%—Adobe Shockwave Player19/2/201816/6/2026
Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.
ModificadaAlta (8.3)11%—HP Aruba Airwave Glass15/2/201817/6/2026
A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.
ModificadaCrítica (9.8)14%💥 ExploitTrustwave Secure WEB Gateway31/12/201717/6/2026
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
ModificadaCrítica (9.8)8.8%—Adobe Shockwave9/12/201717/6/2026
An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (5.5)2.2%💥 ExploitBlackwave Dive Assistant12/9/201717/6/2026
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
ModificadaAlta (7)0.29%—Waves Maxxaudio26/7/201717/6/2026
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
ModificadaCrítica (9.8)6.9%—Adobe Shockwave Player20/6/201717/6/2026
Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)2.2%—Grandstream Wave21/4/201717/6/2026
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.
ModificadaMedia (5.9)0.96%—Grandstream Wave21/4/201717/6/2026
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.
ModificadaAlta (8.1)1.7%—Grandstream Wave21/4/201717/6/2026
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by…
ModificadaCrítica (9.8)1.3%—Dragonwavex Horizon Wireless Radio Firmware6/4/201717/6/2026
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions…
ModificadaAlta (7.8)3.0%—Adobe Shockwave Player14/3/201717/6/2026
Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.
ModificadaAlta (10)3.8%—Adobe Shockwave Player28/10/201517/6/2026
Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaAlta (10)5.6%—Adobe Shockwave Player9/9/201517/6/2026
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.
ModificadaAlta (10)5.1%—Adobe Shockwave Player9/9/201517/6/2026
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.
ModificadaAlta (10)3.8%—Adobe Shockwave Player14/7/201517/6/2026
Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5120.
ModificadaAlta (10)3.8%—Adobe Shockwave Player14/7/201517/6/2026
Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5121.
ModificadaAlta (10)4.7%—Wavelink Connectpro29/5/201517/6/2026
Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header.
ModificadaAlta (10)4.7%—Wavelink Terminal Emulation29/5/201517/6/2026
Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.
ModificadaAlta (9)2.8%—Arubanetworks Airwave25/11/201417/6/2026
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
ModificadaMedia (5.4)0.27%—Roguewaveproductionsllc Wild Women United16/10/201417/6/2026
The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Wavea Toraware Takojyou4/10/201417/6/2026
The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)2.7%—Trustwave ModsecurityDebian Linux15/4/201416/6/2026
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
ModificadaAlta (10)4.8%—Adobe Shockwave Player14/3/201417/6/2026
Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Orbitaley — Vulnerabilidades