Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.43% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (5.5) | 0.40% | — | WiresharkFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Use after free issue in editcap could cause denial of service via crafted capture file | |
| Modificada | Alta (7.5) | 0.81% | — | Fedoraproject FedoraWireshark | 14/5/2024 | 17/6/2026 | MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.5) | 0.42% | — | WiresharkFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Memory handling issue in editcap could cause denial of service via crafted capture file | |
| Aplazada | Media (4.3) | 0.25% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request. | |
| Aplazada | Alta (7.1) | 0.69% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. | |
| Analizada | Alta (7.4) | 0.29% | — | Cisco Wireless LAN Controller SoftwareCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed… | |
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.4% | — | WiresharkFedoraproject Fedora | 26/3/2024 | 17/6/2026 | T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.8) | 3.5% | — | Wireshark | 26/3/2024 | 17/6/2026 | NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file | |
| Analizada | Media (6.1) | 0.52% | — | Laravel Livewire | 19/3/2024 | 17/6/2026 | Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it. | |
| Analizada | Alta (7.5) | 0.71% | — | Teamwire | 5/3/2024 | 17/6/2026 | An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function. | |
| Modificada | Crítica (9.6) | 0.87% | — | Teamwire | 5/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components. | |
| Modificada | Crítica (9.6) | 0.87% | — | Teamwire | 5/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | |
| Modificada | Alta (7.5) | 0.94% | — | Intel Inet Wireless DaemonFedoraproject Fedora | 3/3/2024 | 17/6/2026 | p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails. | |
| Modificada | Alta (7.5) | 1.1% | — | Intel Inet Wireless Daemon | 22/2/2024 | 17/6/2026 | The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key. | |
| Modificada | Alta (7.5) | 1.3% | — | WiresharkFedoraproject Fedora | 21/2/2024 | 17/6/2026 | A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | |
| Modificada | Alta (7.5) | 1.3% | — | Fedoraproject FedoraWireshark | 21/2/2024 | 17/6/2026 | A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | |
| Analizada | Alta (7.5) | 0.98% | — | Wireshark | 21/2/2024 | 17/6/2026 | An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | |
| Aplazada | Baja (2.3) | 0.39% | — | Intel Proset WirelessAIIntel Killer WI FIAI | 14/2/2024 | 17/6/2026 | Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | |
| Modificada | Media (6.5) | 0.46% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access.. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel KillerIntel Proset/wireless | 14/2/2024 | 17/6/2026 | Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |