Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.41% | — | GoldwaveAI | 3/2/2026 | 17/6/2026 | GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands when the file is… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wpwave Hide MY WPAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWave Hide My WP hide_my_wp allows Reflected XSS.This issue affects Hide My WP: from n/a through <= 6.2.12. | |
| Aplazada | Crítica (9.8) | 0.35% | — | Sfwebservice Inwave JobsAI | 6/1/2026 | 30/9/2026 | Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8. | |
| Aplazada | Media (5.3) | 0.27% | — | Silabs Z-wave Protocol ControllerAI | 5/1/2026 | 17/6/2026 | An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads. | |
| Analizada | Alta (8.6) | 0.34% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in the ilog script. This script is being run with root privileges. This issue was… | |
| Analizada | Media (5.1) | 0.39% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions of dvr user, on the server using path traversal in the alog script. This issue was fixed in… | |
| Analizada | Alta (8.6) | 0.49% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version 6.44.44 | |
| Analizada | Media (6.9) | 0.21% | — | Waveterm Wave Terminal | 12/12/2025 | 17/6/2026 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. | |
| Analizada | Crítica (9.8) | 0.57% | — | Waveshare Rs232/485 TO Wifi ETH (B) Firmware | 4/12/2025 | 17/6/2026 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password and username as blank values, allowing attackers to bypass authentication. | |
| Analizada | Media (5.7) | 0.31% | — | Waveshare Rs232/485 TO Wifi ETH (B) Firmware | 4/12/2025 | 17/6/2026 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext. | |
| Analizada | Alta (7.5) | 0.28% | — | Waveshare Rs232/485 TO Wifi ETH (B) Firmware | 4/12/2025 | 17/6/2026 | A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation frames to be broadcast without… | |
| Analizada | Alta (7.5) | 0.26% | — | Waveshare Rs232/485 TO Wifi ETH (B) Firmware | 4/12/2025 | 17/6/2026 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext. | |
| Aplazada | Crítica (9.8) | 0.57% | — | WaveplayerAI | 19/11/2025 | 17/6/2026 | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE | |
| Analizada | Alta (7.2) | 0.99% | — | Arubanetworks Airwave | 18/11/2025 | 17/6/2026 | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system. | |
| Aplazada | Alta (7.6) | 0.32% | — | Silabs Z-wave PIR Sensor Reference DesignAISilabs SisdkAI | 31/10/2025 | 17/6/2026 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1. | |
| Aplazada | Alta (8.5) | 0.20% | — | Digilent WaveformsAI | 15/9/2025 | 17/6/2026 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent WaveForms 3.24.3 and prior versions. | |
| Aplazada | Alta (8.9) | 0.73% | — | Mercury Km08-708h Giga Wifi Wave2AI | 14/9/2025 | 17/6/2026 | A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (7.4) | 4.0% | — | Mercury Km08-708h Giga Wifi Wave2AI | 14/9/2025 | 17/6/2026 | A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1.1. Affected by this issue is the function sub_450B2C of the file /goform/mcr_setSysAdm. The manipulation of the argument ChgUserId leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.8) | 0.61% | — | Powerstick Wave Dual-band Wifi ExtenderAI | 28/7/2025 | 5/7/2026 | An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-supplied input in the /cgi-bin/cgi_vista.cgi executable, which is… | |
| Analizada | Alta (8.4) | 0.30% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the webserver. The vulnerable component is bound… | |
| Analizada | Crítica (9) | 0.25% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up… | |
| Analizada | Crítica (9) | 0.35% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the… | |
| Analizada | Media (4.3) | 0.15% | — | Skywavesolutions WP Firebase Push Notification | 4/7/2025 | 17/6/2026 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attackers to send… | |
| Analizada | Alta (7.5) | 0.60% | — | Trustwave Modsecurity | 21/5/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule… | |
| Aplazada | Media (5) | 0.34% | — | Bluewavelabs CheckmateAI | 15/5/2025 | 17/6/2026 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint. |