Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.31% | — | Wireshark | 10/10/2024 | 17/6/2026 | AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file | |
| Analizada | Media (5.5) | 0.24% | — | Wireshark | 10/10/2024 | 17/6/2026 | ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file | |
| Analizada | Alta (7.7) | 0.85% | 💥 PoC | Laravel Livewire | 8/10/2024 | 17/6/2026 | Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An… | |
| Analizada | Alta (7.2) | 0.62% | — | Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware | 2/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this vulnerability, the attacker must have valid admin… | |
| Analizada | Alta (8.8) | 0.59% | — | Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware | 2/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists because the web-based management interface discloses sensitive… | |
| Analizada | Crítica (9.8) | 0.16% | — | Google Nest Doorbell (battery) FirmwareGoogle Nest CAM (outdoor OR Indoor, Battery) FirmwareGoogle Nest CAM With Floodlight FirmwareGoogle Nest CAM (indoor, Wired) Firmware | 2/10/2024 | 17/6/2026 | According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the… | |
| Analizada | Media (5.1) | 0.42% | — | Wireui | 17/9/2024 | 17/6/2026 | Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query parameter. Malicious actors could exploit this vulnerability by… | |
| Aplazada | Media (5.3) | 0.39% | — | Shandong Star Measurement AND Control Equipment Heating Network Wireless Monitoring SystemAI | 11/9/2024 | 17/6/2026 | A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched… | |
| Modificada | Media (5.5) | 0.21% | — | Wireshark | 10/9/2024 | 17/6/2026 | SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file | |
| Aplazada | Media (5.7) | 0.60% | — | Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI | 10/9/2024 | 17/6/2026 | OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed. | |
| Modificada | Media (5.5) | 0.32% | — | Wireshark | 29/8/2024 | 17/6/2026 | NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file | |
| Aplazada | Media (6.8) | 0.85% | — | Elecom Wireless LAN RouterAI | 1/8/2024 | 17/6/2026 | OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command. | |
| Aplazada | Media (6.8) | 0.36% | — | Elecom Wireless LAN RouterAI | 1/8/2024 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution. | |
| Modificada | Media (4.2) | 0.21% | — | Processwire | 19/7/2024 | 9/7/2026 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique.… | |
| Aplazada | Media (6.8) | 0.32% | — | Mengshen Wireless Door Alarm M70AI | 15/7/2024 | 17/6/2026 | Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach. | |
| Aplazada | Alta (8.4) | 0.49% | — | Arista Wireless Access PointsAI | 27/6/2024 | 17/6/2026 | This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,… | |
| Aplazada | Alta (8.8) | 6.3% | — | Dlink Wireless RoutersAI | 17/6/2024 | 17/6/2026 | Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware. | |
| Aplazada | Media (6.5) | 0.38% | — | Dlink Wireless RouterAI | 17/6/2024 | 17/6/2026 | Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL. | |
| Aplazada | Alta (7.8) | 0.19% | — | Finalwire Airda ExtremeAIFinalwire Aida64 EngineerAIFinalwire Aida64 BusinessAIFinalwire Aida64 Network AuditAI | 10/6/2024 | 7/10/2026 | An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components. | |
| Aplazada | Crítica (9.3) | 0.64% | — | Tripwire EnterpriseAI | 3/6/2024 | 17/6/2026 | An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows… | |
| Aplazada | Media (5.5) | 0.18% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.7) | 0.36% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (4.4) | 0.22% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.3) | 0.22% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Alta (8.2) | 0.34% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |