Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 1.0% | — | Wiremock Studio | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack vectors: via “TestRequester” functionality,… | |
| Modificada | Media (6.5) | 2.8% | — | Wireshark | 25/8/2023 | 17/6/2026 | Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack. | |
| Modificada | Alta (7.5) | 0.51% | — | Wireshark | 24/8/2023 | 17/6/2026 | BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 0.51% | — | Wireshark | 24/8/2023 | 17/6/2026 | CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 0.46% | — | Wireshark | 24/8/2023 | 17/6/2026 | BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (6.7) | 0.18% | — | Intel Proset/wireless Wifi | 11/8/2023 | 17/6/2026 | Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.28% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.60% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.7) | 0.69% | — | Wireguard | 9/8/2023 | 17/6/2026 | The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled.… | |
| Modificada | Media (5.5) | 0.24% | — | Wireshark | 14/7/2023 | 17/6/2026 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.5) | 0.25% | — | Wireshark | 14/7/2023 | 17/6/2026 | Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture file | |
| Modificada | Crítica (9.8) | 2.6% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot. | |
| Modificada | Alta (7.5) | 0.73% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Progress Datadirect Odbc Oracle Wire Protocol Driver | 9/6/2023 | 17/6/2026 | A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying… | |
| Modificada | Media (5.9) | 0.32% | — | Progress Datadirect Odbc Oracle Wire Protocol Driver | 9/6/2023 | 17/6/2026 | An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random… | |
| Modificada | Media (6.5) | 2.3% | — | WiresharkDebian Linux | 7/6/2023 | 17/6/2026 | Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark. | |
| Modificada | Media (6.5) | 2.0% | — | Wireshark | 7/6/2023 | 17/6/2026 | Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark | |
| Modificada | Media (6.5) | 2.3% | — | WiresharkDebian Linux | 7/6/2023 | 17/6/2026 | Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark. | |
| Modificada | Media (6.5) | 1.1% | — | WiresharkDebian Linux | 30/5/2023 | 17/6/2026 | XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 0.53% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 | |
| Modificada | Media (6.8) | 0.29% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in… | |
| Modificada | Media (6.5) | 0.47% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1 |