Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1800 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.75% | — | WiresharkDebian Linux | 16/11/2023 | 17/6/2026 | SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (8.8) | 0.33% | — | Cyberwire PRO Mime Types | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions. | |
| Modificada | Crítica (9.1) | 1.3% | 💥 PoC | Boltwire | 7/11/2023 | 17/6/2026 | An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for… | |
| Modificada | Crítica (9.8) | 1.0% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the cgi_handler… | |
| Modificada | Crítica (9.8) | 1.0% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the gozila_cgi function. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 54% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.64% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Yifanwireless Yf325 Firmware | 11/10/2023 | 17/6/2026 | An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.51% | — | Wireshark | 4/10/2023 | 17/6/2026 | RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (4.7) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware | 27/9/2023 | 17/6/2026 | This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A… | |
| Modificada | Media (6.6) | 0.63% | — | Python WiremockWiremock StudioWiremockWiremock Docker | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and recording from specific target addresses. These restrictions can be configured using the domain names, and in such a case the configuration… | |
| Modificada | Media (5.4) | 0.50% | — | Wiremock StudioWiremock | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. Until WireMock Webhooks Extension… | |
| Modificada | Crítica (10) | 1.0% | — | Wiremock Studio | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack vectors: via “TestRequester” functionality,… | |
| Modificada | Media (6.5) | 2.8% | — | Wireshark | 25/8/2023 | 17/6/2026 | Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack. | |
| Modificada | Alta (7.5) | 0.51% | — | Wireshark | 24/8/2023 | 17/6/2026 | BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 0.51% | — | Wireshark | 24/8/2023 | 17/6/2026 | CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file |