Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for… | |
| Modificada | Crítica (9.8) | 1.0% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the cgi_handler… | |
| Modificada | Crítica (9.8) | 1.0% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the gozila_cgi function. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 54% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.64% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.7) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware | 27/9/2023 | 17/6/2026 | This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A… | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Media (4.8) | 0.37% | — | Visualmodo Borderless | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions. | |
| Modificada | Media (5.3) | 0.75% | — | Agendaless PyramidFedoraproject Fedora | 25/8/2023 | 17/6/2026 | Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a `index.html` file that is located exactly one directory above the location of the static view's… | |
| Modificada | Media (6.7) | 0.18% | — | Intel Proset/wireless Wifi | 11/8/2023 | 17/6/2026 | Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.28% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.60% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 2.6% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot. | |
| Modificada | Alta (7.5) | 0.73% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. | |
| Modificada | Media (6.5) | 0.26% | — | Wafucn Wafu Keyless Smart Lock Firmware | 22/6/2023 | 17/6/2026 | An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack. |