Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for…
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for…
ModificadaCrítica (9.8)1.0%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the cgi_handler…
ModificadaCrítica (9.8)1.0%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the gozila_cgi function.
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)0.77%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)1.3%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)54%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)0.64%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Yifanwireless Yf325 Firmware11/10/202317/6/2026
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (4.7)0.26%—Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware27/9/202317/6/2026
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A…
ModificadaAlta (8.1)1.4%—QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+820/9/20234/8/2026
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and…
ModificadaMedia (4.8)0.37%—Visualmodo Borderless3/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions.
ModificadaMedia (5.3)0.75%—Agendaless PyramidFedoraproject Fedora25/8/202317/6/2026
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a `index.html` file that is located exactly one directory above the location of the static view's…
ModificadaMedia (6.7)0.18%—Intel Proset/wireless Wifi11/8/202317/6/2026
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.28%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.24%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.60%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.7)0.24%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)2.6%—Ucopia Wireless Appliance Firmware29/6/202317/6/2026
An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot.
ModificadaAlta (7.5)0.73%—Ucopia Wireless Appliance Firmware29/6/202317/6/2026
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
ModificadaMedia (6.5)0.26%—Wafucn Wafu Keyless Smart Lock Firmware22/6/202317/6/2026
An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.
Orbitaley — Vulnerabilidades