Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1800 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.43%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AnalizadaMedia (5.5)0.40%—WiresharkFedoraproject Fedora14/5/202417/6/2026
Use after free issue in editcap could cause denial of service via crafted capture file
ModificadaAlta (7.5)0.81%—Fedoraproject FedoraWireshark14/5/202417/6/2026
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
ModificadaMedia (5.5)0.42%—WiresharkFedoraproject Fedora14/5/202417/6/2026
Memory handling issue in editcap could cause denial of service via crafted capture file
AplazadaMedia (4.3)0.25%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.
AplazadaAlta (7.1)0.69%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product.
AnalizadaAlta (7.4)0.29%—Cisco Wireless LAN Controller SoftwareCisco IOS XE27/3/202417/6/2026
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed…
AnalizadaAlta (8.6)0.63%—Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software27/3/202417/6/2026
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this…
ModificadaAlta (7.5)1.4%—WiresharkFedoraproject Fedora26/3/202417/6/2026
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.8)3.5%—Wireshark26/3/202417/6/2026
NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file
AnalizadaMedia (6.1)0.52%—Laravel Livewire19/3/202417/6/2026
Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.
AnalizadaAlta (7.5)0.71%—Teamwire5/3/202417/6/2026
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
ModificadaCrítica (9.6)0.87%—Teamwire5/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.
ModificadaCrítica (9.6)0.87%—Teamwire5/3/202417/6/2026
Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.
ModificadaAlta (7.5)0.94%—Intel Inet Wireless DaemonFedoraproject Fedora3/3/202417/6/2026
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
ModificadaAlta (7.5)1.1%—Intel Inet Wireless Daemon22/2/202417/6/2026
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
ModificadaAlta (7.5)1.3%—WiresharkFedoraproject Fedora21/2/202417/6/2026
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
ModificadaAlta (7.5)1.3%—Fedoraproject FedoraWireshark21/2/202417/6/2026
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
AnalizadaAlta (7.5)0.98%—Wireshark21/2/202417/6/2026
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
AplazadaBaja (2.3)0.39%—Intel Proset WirelessAIIntel Killer WI FIAI14/2/202417/6/2026
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
ModificadaMedia (6.5)0.46%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (5.5)0.19%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.37%—Intel KillerIntel Proset/wireless14/2/202417/6/2026
Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.