Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.49% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper… | |
| Analizada | Media (6.5) | 0.23% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from the lack of proper… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from the lack of… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Sslplugins SSL Wireless SMS NotificationAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.5.0. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sslplugins SSL Wireless SMS NotificationAI | 31/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.6.0. | |
| Aplazada | Alta (8.1) | 0.42% | — | Sierrawireless AirvantageAI | 21/12/2024 | 17/6/2026 | The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the device. This could enable an attacker to configure, manage, and execute AT commands… | |
| Aplazada | Alta (7.1) | 0.21% | — | Thomas Hoefter Onlywire Multi AutosubmitterAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Onlywire Multi Autosubmitter onlywire-multi-autosubmitter allows Stored XSS.This issue affects Onlywire Multi Autosubmitter: from n/a through <= 1.2.4. | |
| Analizada | Media (5.5) | 0.30% | — | Wireshark | 21/11/2024 | 17/6/2026 | ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file | |
| Analizada | Media (5.5) | 0.27% | — | Wireshark | 21/11/2024 | 17/6/2026 | FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file | |
| Analizada | Media (6.5) | 0.33% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+30 | 18/11/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to… | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.28% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Aplazada | Media (4.6) | 0.18% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Media (6.8) | 0.24% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access. | |
| Analizada | Media (4.6) | 0.18% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before version 23.40 may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Media (6.8) | 0.30% | — | Intel Wireless BluetoothAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (6.8) | 0.24% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access. | |
| Aplazada | Alta (8.8) | 0.56% | — | Cypress Cyw43455AIBroadcom Wireless Combo ChipsAI | 11/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack. | |
| Aplazada | Media (5.5) | 0.39% | — | Cypress Wireless Combo ChipsAIBroadcom Wireless Combo ChipsAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack. | |
| Aplazada | Baja (3.5) | 0.36% | — | Cypress Wireless ComboAIBroadcom Wireless ComboAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack. | |
| Aplazada | Media (5.5) | 0.39% | — | Cypress Wireless Combo ChipsAIBroadcom Wireless Combo ChipsAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack. | |
| Aplazada | Crítica (10) | 3.1% | — | Cisco Unified Industrial Wireless SoftwareAICisco Ultra Reliable Wireless BackhaulAI | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This… |