Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.43% | — | Wavelog | 14/10/2024 | 17/6/2026 | Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. | |
| Aplazada | Alta (8.2) | 0.44% | — | Wisdomcity ZwaveAI | 11/10/2024 | 5/7/2026 | An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Analizada | Alta (7.5) | 0.82% | — | Trustwave Modsecurity | 9/10/2024 | 17/6/2026 | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large… | |
| Analizada | Media (6.9) | 0.57% | — | Wavelog | 7/9/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.4) | 12% | — | Ligowave UnityAILigowave PROAILigowave MimoAILigowave APC PropellerAI | 16/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through… | |
| Analizada | Media (6.1) | 0.44% | — | Carrierwave Project Carrierwave | 24/3/2024 | 17/6/2026 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by… | |
| Aplazada | Alta (8.8) | 0.34% | — | Silabs Z-wave END DevicesAI | 7/3/2024 | 17/6/2026 | The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | |
| Analizada | Media (6.5) | 0.27% | — | Silabs Z-wave Pc-based Controller | 21/2/2024 | 17/6/2026 | Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier. | |
| Analizada | Media (6.5) | 0.25% | — | Silabs Z-wave Pc-based Controller | 21/2/2024 | 17/6/2026 | Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier. | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the… | |
| Modificada | Alta (7.3) | 0.37% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow… | |
| Modificada | Alta (7.8) | 0.38% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow… | |
| Modificada | Alta (7.8) | 0.42% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.42% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.41% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds… | |
| Modificada | Alta (7.8) | 0.44% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.36% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow… |