Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.84% | — | Muwire Project Muwire | 15/7/2021 | 17/6/2026 | MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior to version 0.8.8 can be de-anonymized by an attacker who knows their full ID. An attacker could send a message with a subject line containing a URL with an HTML image… | |
| Modificada | Media (4.3) | 0.31% | — | Wire | 13/7/2021 | 17/6/2026 | Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was introduced for users running iOS 13 or higher. This new websocket implementation is… | |
| Modificada | Media (6.1) | 0.83% | — | Wire-webapp | 15/6/2021 | 17/6/2026 | wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-webapp prior to version 2021-06-01-production.0. If a user is instructed to open an image in a new tab (right click -> open in new tab, or copy the URL and paste it in the URL bar), an the image… | |
| Modificada | Crítica (9.6) | 1.5% | — | Wire Restund | 11/6/2021 | 17/6/2026 | Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship… | |
| Modificada | Alta (7.5) | 1.9% | — | WiresharkOracle Enterprise Manager OPS CenterOracle Instantis EnterprisetrackOracle ZFS Storage Appliance KIT+1 | 7/6/2021 | 17/6/2026 | Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (6.5) | 0.92% | — | Wire | 3/6/2021 | 17/6/2026 | wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause a denial of service between users. If a user has an invalid assetID for their profile picture and it contains the " character, it will cause the iOS client to crash. The… | |
| Modificada | Media (6.5) | 0.48% | — | Wire | 3/6/2021 | 17/6/2026 | wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conversation - Self user is added to an existing conversation - All the participants… | |
| Modificada | Media (6.5) | 3.1% | — | Alfa Awus036h FirmwareCisco Meraki Gr10 FirmwareCisco Meraki Gr60 FirmwareCisco Meraki Mr20 Firmware+91 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP… | |
| Modificada | Media (6.5) | 2.9% | — | Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+190 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. | |
| Modificada | Media (5.3) | 6.5% | — | NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+162 | 11/5/2021 | 17/6/2026 | An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to… | |
| Modificada | Baja (3.5) | 3.6% | — | Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+177 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary… | |
| Modificada | Baja (2.6) | 2.6% | — | Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+164 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or… | |
| Modificada | Crítica (9.1) | 1.6% | — | Asynkron Wire | 11/5/2021 | 17/6/2026 | Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged… | |
| Modificada | Crítica (9.8) | 1.8% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, but can be enabled by sending a crafted request to a web management interface endpoint. Requests… | |
| Modificada | Alta (7.5) | 1.2% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device configuration password in cleartext when using the GETPASS command. As such, any… | |
| Modificada | Alta (7.5) | 1.1% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prepended. Commands in this category are able to directly read the contents of the… | |
| Modificada | Media (6.5) | 2.0% | — | WiresharkFedoraproject FedoraOracle ZFS Storage Appliance KITDebian Linux | 23/4/2021 | 17/6/2026 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 0.98% | — | Abus Secvest Wireless Alarm System Fuaa50000 Firmware | 21/4/2021 | 17/6/2026 | The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the… | |
| Modificada | Media (6.5) | 1.1% | — | Wire-webapp | 2/4/2021 | 17/6/2026 | wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be sent into the most recently used chat when the user does not actively give focus to the input… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP. | |
| Modificada | Alta (7.5) | 2.0% | — | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required. | |
| Modificada | Media (6.5) | 1.1% | — | Wire Server | 26/3/2021 | 17/6/2026 | wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-02, the client metadata of all users was exposed in the `GET /users/list-clients` endpoint. The endpoint could be used by any logged in user who could request client… | |
| Modificada | Media (4.4) | 0.23% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software | 24/3/2021 | 17/6/2026 | A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability… | |
| Modificada | Media (6.7) | 0.27% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software | 24/3/2021 | 17/6/2026 | A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability… |