Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.46%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (5.5)0.19%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.41%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..
ModificadaMedia (6.5)0.42%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.36%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.7)0.23%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)1.1%—Sierrawireless Aleos25/12/202317/6/2026
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
ModificadaAlta (7.5)0.65%—Automattic Woocommerce Gocardless20/12/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
ModificadaCrítica (9.8)1.6%—Nintendo DS Wireless Communication20/12/202317/6/2026
DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaMedia (6.1)0.41%—Ruckuswireless R750 FirmwareRuckuswireless R650 FirmwareRuckuswireless R730 FirmwareRuckuswireless T750 Firmware+337/12/202317/6/2026
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information…
ModificadaMedia (6.5)0.18%—Assaabloy Yale Keyless Smart Lock Firmware5/12/202317/6/2026
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
ModificadaMedia (5.5)0.21%—Sierrawireless Aleos4/12/202317/6/2026
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
ModificadaMedia (6.8)0.30%—Sierrawireless Aleos4/12/202317/6/2026
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.
ModificadaAlta (7.2)0.63%—Sierrawireless Aleos4/12/202317/6/2026
When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.
ModificadaAlta (7.5)0.88%—Sierrawireless AleosDebian Linux4/12/202317/6/2026
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of…
ModificadaMedia (4.8)0.46%—Sierrawireless Aleos4/12/202317/6/2026
The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.
ModificadaMedia (5.4)0.50%—Sierrawireless Aleos4/12/202317/6/2026
The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.
ModificadaAlta (7.5)2.3%💥 PoCSierrawireless Aleos4/12/202317/6/2026
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten…
ModificadaAlta (7.5)0.82%—Sierrawireless Aleos29/11/202317/6/2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as…
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as…
Orbitaley — Vulnerabilidades