Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.34% | — | Ruckuswireless R310 FirmwareRuckuswireless R500 FirmwareRuckuswireless R600 FirmwareRuckuswireless T300 Firmware+10 | 20/1/2023 | 17/6/2026 | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone… | |
| Modificada | Crítica (9.8) | 0.55% | — | Ruckuswireless R310 FirmwareRuckuswireless R500 FirmwareRuckuswireless R600 FirmwareRuckuswireless T300 Firmware+10 | 20/1/2023 | 17/6/2026 | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone… | |
| Modificada | Alta (7.2) | 0.96% | — | Cisco Rv160 VPN Router FirmwareCisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE Firmware | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user input. An… | |
| Modificada | Media (6.5) | 0.61% | — | Cisco IP Phone 7800 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 FirmwareCisco IP Phone 7832 Firmware+18 | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.5) | 2.2% | 💥 PoC | Ruckuswireless Sz-300 FirmwareRuckuswireless Sz-144 FirmwareRuckuswireless Sz-100 FirmwareRuckuswireless VSZ Firmware | 18/1/2023 | 9/7/2026 | DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attacks via crafted request. | |
| Modificada | Alta (7.5) | 11% | — | Netcommwireless Nf20 FirmwareNetcommwireless Nf20mesh FirmwareNetcommwireless Nl1902 Firmware | 11/1/2023 | 17/6/2026 | Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the… | |
| Modificada | Crítica (9.8) | 7.2% | — | Netcommwireless Nf20 FirmwareNetcommwireless Nf20mesh FirmwareNetcommwireless Nl1902 Firmware | 11/1/2023 | 17/6/2026 | On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location. | |
| Analizada | Crítica (9.8) | 1.7% | — | Sierrawireless Aleos | 26/12/2022 | 17/6/2026 | The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow. | |
| Modificada | Media (6.5) | 0.39% | — | Sierrawireless Mgos | 26/12/2022 | 17/6/2026 | Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing). | |
| Modificada | Crítica (9.8) | 0.90% | — | Sierrawireless Airlink Mobility Manager | 26/12/2022 | 17/6/2026 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.32% | — | Intel Wi-fi 6E Ax411 FirmwareIntel Wi-fi 6E Ax211 FirmwareIntel Wi-fi 6E Ax210 FirmwareIntel Wi-fi 6E Ax201 Firmware+10 | 11/11/2022 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.42% | — | Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+338 | 11/11/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lesspipe Project Lesspipe | 1/11/2022 | 17/6/2026 | lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash. | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Wireless LAN Controller Software | 30/9/2022 | 17/6/2026 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this… | |
| Modificada | Media (5.4) | 0.35% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail. | |
| Modificada | Alta (8.1) | 0.67% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM. | |
| Modificada | Media (6.5) | 0.66% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information. | |
| Modificada | Media (4.2) | 0.47% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information. | |
| Modificada | Alta (7.5) | 0.82% | — | Redhat Openshift Serverless | 26/8/2022 | 17/6/2026 | It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0. | |
| Modificada | Media (6.5) | 0.35% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access. |