Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.80% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Killer AC 1550 Firmware+3 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.83% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.8) | 0.16% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Alta (7.8) | 0.24% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Killer AC 1550 Firmware+9 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Baja (3.3) | 0.20% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.1) | 0.21% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Alta (7.5) | 1.3% | — | Namelessmc Nameless | 15/8/2022 | 17/6/2026 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | |
| Modificada | Alta (8.2) | 0.70% | — | Namelessmc Nameless | 15/8/2022 | 17/6/2026 | Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. | |
| Modificada | Media (5.5) | 0.18% | — | Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+21 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using… | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Alta (8.1) | 1.0% | — | Simplessus | 28/6/2022 | 17/6/2026 | A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd leads to path traversal. The attack may be… | |
| Modificada | Alta (7.5) | 1.1% | — | Simplessus | 28/6/2022 | 17/6/2026 | A vulnerability was found in Simplessus 3.7.7. It has been declared as critical. This vulnerability affects unknown code of the component Cookie Handler. The manipulation of the argument UWA_SID leads to sql injection (Time). The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.71% | — | Ruckuswireless Zonedirector Firmware | 27/6/2022 | 9/7/2026 | Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0. | |
| Modificada | Media (6.5) | 0.53% | — | Seamless Donations Project Seamless Donations | 20/6/2022 | 17/6/2026 | The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.9) | 1.5% | — | Agendaless Waitress | 31/5/2022 | 17/6/2026 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread closing a socket while the main thread is about to call select(). This will lead to the main thread raising an exception that is not handled and then causing the entire… | |
| Modificada | Crítica (10) | 20% | — | Cisco Wireless LAN Controller 8.10.151.0Cisco Wireless LAN Controller 8.10.162.0 | 15/4/2022 | 17/6/2026 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password… | |
| Modificada | Alta (7.5) | 1.8% | — | Agendaless WaitressDebian Linux | 17/3/2022 | 17/6/2026 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This… |