Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1800 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.31%—Wireshark10/10/202417/6/2026
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
AnalizadaMedia (5.5)0.24%—Wireshark10/10/202417/6/2026
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
AnalizadaAlta (7.7)0.85%💥 PoCLaravel Livewire8/10/202417/6/2026
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An…
AnalizadaAlta (7.2)0.62%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware2/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this vulnerability, the attacker must have valid admin…
AnalizadaAlta (8.8)0.59%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware2/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists because the web-based management interface discloses sensitive…
AnalizadaCrítica (9.8)0.16%—Google Nest Doorbell (battery) FirmwareGoogle Nest CAM (outdoor OR Indoor, Battery) FirmwareGoogle Nest CAM With Floodlight FirmwareGoogle Nest CAM (indoor, Wired) Firmware2/10/202417/6/2026
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the…
AnalizadaMedia (5.1)0.42%—Wireui17/9/202417/6/2026
Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query parameter. Malicious actors could exploit this vulnerability by…
AplazadaMedia (5.3)0.39%—Shandong Star Measurement AND Control Equipment Heating Network Wireless Monitoring SystemAI11/9/202417/6/2026
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched…
ModificadaMedia (5.5)0.21%—Wireshark10/9/202417/6/2026
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
AplazadaMedia (5.7)0.60%—Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI10/9/202417/6/2026
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
ModificadaMedia (5.5)0.32%—Wireshark29/8/202417/6/2026
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
AplazadaMedia (6.8)0.85%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.
AplazadaMedia (6.8)0.36%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
ModificadaMedia (4.2)0.21%—Processwire19/7/20249/7/2026
Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique.…
AplazadaMedia (6.8)0.32%—Mengshen Wireless Door Alarm M70AI15/7/202417/6/2026
Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.
AplazadaAlta (8.4)0.49%—Arista Wireless Access PointsAI27/6/202417/6/2026
This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,…
AplazadaAlta (8.8)6.3%—Dlink Wireless RoutersAI17/6/202417/6/2026
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
AplazadaMedia (6.5)0.38%—Dlink Wireless RouterAI17/6/202417/6/2026
Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL.
AplazadaAlta (7.8)0.19%—Finalwire Airda ExtremeAIFinalwire Aida64 EngineerAIFinalwire Aida64 BusinessAIFinalwire Aida64 Network AuditAI10/6/20247/10/2026
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.
AplazadaCrítica (9.3)0.64%—Tripwire EnterpriseAI3/6/202417/6/2026
An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows…
AplazadaMedia (5.5)0.18%—Intel Wireless BluetoothAI16/5/202417/6/2026
Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (4.7)0.36%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (4.4)0.22%—Intel Wireless BluetoothAI16/5/202417/6/2026
Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access.
AplazadaMedia (4.3)0.22%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaAlta (8.2)0.34%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.