Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Alta (8.8) | 1.5% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. | |
| Modificada | Alta (8.8) | 1.0% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality. | |
| Modificada | Alta (8.8) | 0.79% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change. | |
| Modificada | Alta (8.8) | 0.98% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. | |
| Modificada | Media (6.5) | 0.94% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables. | |
| Modificada | Alta (8.8) | 0.93% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware | 22/10/2021 | 17/6/2026 | The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk. | |
| Modificada | Alta (7.5) | 1.9% | — | Signalwire Freeswitch | 18/10/2021 | 17/6/2026 | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value. | |
| Modificada | Crítica (9.8) | 1.7% | — | Glasswire | 18/10/2021 | 17/6/2026 | A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution. | |
| Modificada | Media (5.5) | 0.27% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 Firmware+12 | 6/10/2021 | 17/6/2026 | A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted input to a debug shell command. A… | |
| Modificada | Crítica (9.8) | 0.90% | — | Wire-server | 4/10/2021 | 17/6/2026 | Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. As the short-lived token is only meant as means of authentication by the client… | |
| Modificada | Media (4.6) | 0.18% | — | Wire | 4/10/2021 | 17/6/2026 | Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at rest by generating encryption keys via the Secure Enclave, however it will fail silently if no… | |
| Modificada | Crítica (9.8) | 1.5% | — | Wire | 4/10/2021 | 17/6/2026 | Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an authentication cookie. See wire-ios-sync-engine… | |
| Modificada | Media (5.7) | 0.71% | — | Wire Server | 30/9/2021 | 17/6/2026 | wire-server is an open-source back end for Wire, a secure collaboration platform. Before version 2.106.0, the CORS ` Access-Control-Allow-Origin ` header set by `nginz` is set for all subdomains of `.wire.com` (including `wire.com`). This means that if somebody were to find an XSS vector in any of the subdomains, they… | |
| Modificada | Crítica (10) | 1.1% | — | Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1420 Gateway FirmwareEmerson Wireless 1552wu Gateway Firmware | 29/9/2021 | 17/6/2026 | There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway. | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco Embedded Wireless Controller | 23/9/2021 | 17/6/2026 | A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XECisco Embedded Wireless ControllerCisco Catalyst 9800 Firmware | 23/9/2021 | 17/6/2026 | Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco Aironet 1542d FirmwareCisco Aironet 1562d FirmwareCisco Aironet 1815m FirmwareCisco Aironet 1830e Firmware+37 | 23/9/2021 | 17/6/2026 | A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A… | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a… | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to exhaust device BT resources and eventually trigger a crash via… | |
| Modificada | Media (5.3) | 0.51% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a… | |
| Modificada | Media (6.5) | 0.56% | — | MI True Wireless Earbuds Basic 2 FirmwareBluetrum Ab5376t FirmwareBluetrum Bt8896a Firmware | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Cisco Application Extension PlatformCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router Firmware+1 | 18/8/2021 | 17/6/2026 | A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco IP Phone 8800 FirmwareCisco IP Phone 8800 Series With Multiplatform FirmwareCisco IP Phone 8811 FirmwareCisco IP Phone 8811 With Multiplatform Firmware+11 | 22/7/2021 | 17/6/2026 | The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone… | |
| Modificada | Alta (7.5) | 3.4% | — | WiresharkDebian Linux | 20/7/2021 | 17/6/2026 | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file |