Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Signalwire Sofia-sipDebian Linux26/5/202317/6/2026
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and…
ModificadaAlta (7.5)1.6%—WiresharkDebian Linux26/5/202317/6/2026
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
ModificadaMedia (6.5)1.8%—WiresharkDebian Linux26/5/202317/6/2026
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
ModificadaMedia (6.5)0.88%—WiresharkDebian Linux26/5/202317/6/2026
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
ModificadaMedia (6.5)1.8%—WiresharkDebian Linux26/5/202317/6/2026
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
ModificadaMedia (6.5)1.6%—WiresharkDebian Linux26/5/202317/6/2026
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
ModificadaMedia (6.5)0.88%—WiresharkDebian Linux26/5/202317/6/2026
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
ModificadaAlta (7.5)1.3%—Savysoda Wifi HD Wireless Disk Drive17/5/202317/6/2026
savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.
ModificadaAlta (7.5)14%—Aigital Wireless-n Repeater Mini Router Firmware2/5/202317/6/2026
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.
ModificadaMedia (5.4)29%—Aigital Wireless-n Repeater Mini Router Firmware28/4/202317/6/2026
A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup.
ModificadaCrítica (9.8)2.2%—Aigital Wireless-n Repeater Mini Router Firmware26/4/20239/7/2026
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
ModificadaMedia (6.5)1.0%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
ModificadaMedia (6.5)4.1%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.5)4.6%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
ModificadaMedia (6.7)0.24%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator…
ModificadaMedia (5.5)0.26%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this…
ModificadaMedia (5.3)0.44%—Silabs Wireless Smart Ubiquitous Network Linux Border Router Firmware21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.
ModificadaAlta (7.1)0.65%—WiresharkDebian Linux6/3/202317/6/2026
ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitRuckuswireless Ruckus Wireless AdminRuckuswireless Smartzone APCommscope Ruckus Smartzone Firmware13/2/202317/6/2026
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
ModificadaMedia (4.9)12%—Sierrawireless Aleos10/2/202317/6/2026
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
ModificadaAlta (8.8)2.3%💥 PoCSierrawireless Aleos10/2/202317/6/2026
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
ModificadaMedia (5.3)0.47%—Wireguard29/1/202317/6/2026
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.
ModificadaMedia (6.5)0.73%—Wire28/1/202317/6/2026
wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conversation can remove a Bot from a Conversation due to a missing permissions check. Only Conversation admins should be able to remove Bots. Regular Conversations are not…
ModificadaMedia (5.3)0.62%—Wire-webapp27/1/202317/6/2026
Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptional Conditions. In the wire-webapp, certain combinations of Markdown formatting can trigger an unhandled error in the conversion to HTML representation. The error makes it impossible to display the…
ModificadaMedia (6.5)0.85%—Wireshark26/1/202317/6/2026
Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Orbitaley — Vulnerabilidades