Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.39% | — | Sierrawireless Mgos | 26/12/2022 | 17/6/2026 | Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing). | |
| Modificada | Crítica (9.8) | 0.90% | — | Sierrawireless Airlink Mobility Manager | 26/12/2022 | 17/6/2026 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Alta (7.5) | 2.5% | — | Wireshark | 9/12/2022 | 17/6/2026 | Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows | |
| Modificada | Media (4.7) | 0.28% | — | Wire | 18/11/2022 | 17/6/2026 | Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.32% | — | Intel Wi-fi 6E Ax411 FirmwareIntel Wi-fi 6E Ax211 FirmwareIntel Wi-fi 6E Ax210 FirmwareIntel Wi-fi 6E Ax201 Firmware+10 | 11/11/2022 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.5) | 0.42% | — | Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+338 | 11/11/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 0.29% | — | Processwire | 31/10/2022 | 9/7/2026 | ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). | |
| Modificada | Media (6.1) | 0.45% | — | Processwire | 31/10/2022 | 9/7/2026 | ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload. | |
| Modificada | Alta (7.5) | 0.87% | — | WiresharkFedoraproject Fedora | 27/10/2022 | 17/6/2026 | Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (8.1) | 0.65% | — | Wire Server | 18/10/2022 | 17/6/2026 | Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, the attacker can delete all SAML authenticated accounts of a… | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Wireless LAN Controller Software | 30/9/2022 | 17/6/2026 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this… | |
| Modificada | Media (5.5) | 2.3% | — | WiresharkFedoraproject Fedora | 13/9/2022 | 17/6/2026 | Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.4) | 0.35% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail. | |
| Modificada | Alta (8.1) | 0.67% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM. | |
| Modificada | Media (6.5) | 0.66% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information. | |
| Modificada | Media (4.2) | 0.47% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information. | |
| Modificada | Media (6.5) | 0.35% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Alta (7.5) | 0.80% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Killer AC 1550 Firmware+3 | 18/8/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.83% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access. |