Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)6.5%—NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+16211/5/202117/6/2026
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to…
ModificadaBaja (3.5)3.6%—Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+17711/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary…
ModificadaBaja (2.6)2.6%—Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+16411/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or…
ModificadaCrítica (9.8)1.6%—Librewireless LS9 Firmware3/5/202117/6/2026
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged…
ModificadaCrítica (9.8)1.8%—Librewireless LS9 Firmware3/5/202117/6/2026
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, but can be enabled by sending a crafted request to a web management interface endpoint. Requests…
ModificadaAlta (7.5)1.2%—Librewireless LS9 Firmware3/5/202117/6/2026
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device configuration password in cleartext when using the GETPASS command. As such, any…
ModificadaAlta (7.5)1.1%—Librewireless LS9 Firmware3/5/202117/6/2026
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prepended. Commands in this category are able to directly read the contents of the…
ModificadaAlta (7.5)0.98%—Abus Secvest Wireless Alarm System Fuaa50000 Firmware21/4/202117/6/2026
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the…
ModificadaAlta (7.5)4.2%💥 ExploitAcexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
ModificadaAlta (7.5)2.0%—Acexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.
ModificadaMedia (4.4)0.23%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability…
ModificadaMedia (6.7)0.27%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability…
ModificadaAlta (7.5)1.5%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker…
ModificadaMedia (6.1)0.82%—Acexy Wireless-n Wifi Repeater Project Acexy Wireless-n Wifi Repeater Firmware18/3/202117/6/2026
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).
ModificadaAlta (7.5)3.0%—Emerson Smart Wireless Gateway 1420 Firmware10/3/202117/6/2026
Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.
ModificadaAlta (8.8)2.7%—Emerson Wireless 1420 Gateway Firmware10/3/202117/6/2026
Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application.
ModificadaMedia (5.2)0.42%—Intel Proset/wireless WifiIntel Killer17/2/202117/6/2026
Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b>&nbsp;</b>via adjacent access.
ModificadaAlta (7.8)0.99%—Less-openui5 Project Less-openui516/2/202117/6/2026
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, those resources might contain JavaScript code which will be executed in the context…
ModificadaAlta (7.5)3.7%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be restricted on an affected system. These…
ModificadaAlta (7.5)3.7%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be restricted on an affected system. These…
ModificadaCrítica (9.8)4.2%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not…
ModificadaCrítica (9.8)4.5%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not…
ModificadaCrítica (9.8)5.4%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not…
ModificadaCrítica (9.8)4.2%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not…
ModificadaCrítica (9.8)4.2%—Cisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE FirmwareCisco Rv260w Wireless-ac VPN Router Firmware+14/2/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not…