Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.46% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access.. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.41% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.. | |
| Modificada | Media (6.5) | 0.42% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.36% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.7) | 0.23% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.1% | — | Sierrawireless Aleos | 25/12/2023 | 17/6/2026 | OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token. | |
| Modificada | Alta (7.5) | 0.65% | — | Automattic Woocommerce Gocardless | 20/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6. | |
| Modificada | Crítica (9.8) | 1.6% | — | Nintendo DS Wireless Communication | 20/12/2023 | 17/6/2026 | DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (6.1) | 0.41% | — | Ruckuswireless R750 FirmwareRuckuswireless R650 FirmwareRuckuswireless R730 FirmwareRuckuswireless T750 Firmware+33 | 7/12/2023 | 17/6/2026 | A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information… | |
| Modificada | Media (6.5) | 0.18% | — | Assaabloy Yale Keyless Smart Lock Firmware | 5/12/2023 | 17/6/2026 | Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original. | |
| Modificada | Media (5.5) | 0.21% | — | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal. | |
| Modificada | Media (6.8) | 0.30% | — | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server. | |
| Modificada | Alta (7.2) | 0.63% | — | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access. | |
| Modificada | Alta (7.5) | 0.88% | — | Sierrawireless AleosDebian Linux | 4/12/2023 | 17/6/2026 | The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of… | |
| Modificada | Media (4.8) | 0.46% | — | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition. | |
| Modificada | Media (5.4) | 0.50% | — | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted. | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Sierrawireless Aleos | 4/12/2023 | 17/6/2026 | The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten… | |
| Modificada | Alta (7.5) | 0.82% | — | Sierrawireless Aleos | 29/11/2023 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as… |