Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.21% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.8) | 0.16% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+5 | 18/8/2022 | 17/6/2026 | Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Alta (7.8) | 0.24% | — | Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Killer AC 1550 Firmware+9 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Baja (3.3) | 0.20% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.1) | 0.21% | — | Intel Wi-fi 6 Ax411 FirmwareIntel Wi-fi 6 Ax211 FirmwareIntel Wi-fi 6 Ax210 FirmwareIntel Wi-fi 6 Ax201 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 0.37% | — | Intel Wireless-ac 9560 FirmwareIntel Dual Band Wireless-ac 3165 FirmwareIntel Dual Band Wireless-ac 3168 FirmwareIntel Wireless-ac 9462 Firmware+14 | 18/8/2022 | 17/6/2026 | Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (5.5) | 0.18% | — | Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+21 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using… | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (6.1) | 0.71% | — | Ruckuswireless Zonedirector Firmware | 27/6/2022 | 9/7/2026 | Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0. | |
| Modificada | Media (6.1) | 0.84% | — | Wire-webapp | 25/6/2022 | 17/6/2026 | Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context of the victim allowing the attacker to… | |
| Modificada | Media (6.5) | 0.67% | — | Wire | 23/6/2022 | 17/6/2026 | wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an… | |
| Modificada | Crítica (9.8) | 3.8% | — | Signalwire Sofia-sipDebian Linux | 31/5/2022 | 17/6/2026 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or… | |
| Modificada | Alta (7.5) | 2.1% | — | Signalwire Sofia-sipDebian Linux | 31/5/2022 | 17/6/2026 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) - 1) == 0)`, which will make `n` bigger and… | |
| Modificada | Alta (7.5) | 1.9% | — | Signalwire Sofia-sipDebian Linux | 31/5/2022 | 17/6/2026 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a patch for this issue. | |
| Modificada | Media (6.1) | 1.00% | — | Wire-webapp | 20/4/2022 | 17/6/2026 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and views such a malicious message, arbitrary… | |
| Modificada | Crítica (10) | 20% | — | Cisco Wireless LAN Controller 8.10.151.0Cisco Wireless LAN Controller 8.10.162.0 | 15/4/2022 | 17/6/2026 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password… | |
| Modificada | Alta (7.5) | 1.4% | — | Wire-server | 13/4/2022 | 17/6/2026 | Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafted object causing a hash collision. This collision causes the server to spend at least quadratic time parsing it which can lead to a denial of service for a heavily used… | |
| Modificada | Alta (8.1) | 0.70% | — | Wire-server | 16/3/2022 | 17/6/2026 | wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to bypass SAML SSO and impersonate any Wire user with SAML credentials. In teams with SAML, but without SCIM, it was possible to create new… | |
| Modificada | Media (6.5) | 1.2% | — | WireWire-ios-transport | 11/3/2022 | 17/6/2026 | Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire… | |
| Modificada | Media (6.5) | 1.8% | — | Pfsense-pkg-wireguard | 10/3/2022 | 17/6/2026 | Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder. |