Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
131 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.44% | — | Philips Taolight Smart Wi-fi WIZ Connected LED Bulb 9290022656 Firmware | 14/11/2019 | 17/6/2026 | On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is… | |
| Modificada | Alta (8.8) | 0.62% | — | Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+9 | 14/11/2019 | 17/6/2026 | Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via adjacent access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+9 | 14/11/2019 | 17/6/2026 | Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access. | |
| Modificada | Crítica (9.8) | 2.4% | — | Autopi Wi-fi/nb FirmwareAutopi 4g/lte Firmware | 14/10/2019 | 17/6/2026 | AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash function output (input is only 8 characters),… | |
| Modificada | Media (6.5) | 1.4% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely… | |
| Modificada | Alta (7.1) | 1.6% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and… | |
| Modificada | Media (5.9) | 2.0% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi… | |
| Modificada | Alta (7.5) | 1.4% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on. | |
| Modificada | Alta (7.5) | 1.5% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method. | |
| Modificada | Media (6.7) | 0.42% | — | Supermicro X11ssz FirmwareSupermicro X11ssv FirmwareSupermicro X11ssql FirmwareSupermicro X11ssq Firmware+106 | 9/7/2018 | 17/6/2026 | Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware. | |
| Modificada | Alta (8.8) | 0.90% | — | Vgate Icar 2 Wi-fi Obd2 Firmware | 30/5/2018 | 17/6/2026 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed,… | |
| Modificada | Media (6.5) | 0.47% | — | Vgate Icar 2 Wi-fi Obd2 Firmware | 30/5/2018 | 17/6/2026 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public. | |
| Modificada | Alta (8.8) | 0.51% | — | Vgate Icar 2 Wi-fi Obd2 Firmware | 30/5/2018 | 17/6/2026 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication. | |
| Modificada | Media (6.1) | 0.77% | — | Rletech Wi-mgr FirmwareRletech Fds-wi Firmware | 21/2/2018 | 17/6/2026 | An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP. | |
| Modificada | Crítica (9.8) | 2.3% | — | Nttdocomo Wi-fi Station L-02f Firmware | 13/11/2017 | 17/6/2026 | Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Nttdocomo Wi-fi Station L-02f Firmware | 15/9/2017 | 17/6/2026 | Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.8% | — | Nttdocomo Wi-fi Station L-02f Firmware | 15/9/2017 | 17/6/2026 | Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account. | |
| Modificada | Crítica (9.8) | 64% | 💥 Exploit | Broadcom Bcm43xx Wi-fi Chipset Firmware | 4/6/2017 | 17/6/2026 | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. | |
| Modificada | Alta (8.8) | 2.0% | — | Broadcom Hardmac Wi-fi SOC Firmware | 5/4/2017 | 17/6/2026 | On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition Information Element (FT-IE). | |
| Modificada | Alta (7.5) | 37% | 💥 Exploit | Hak5 Wi-fi Pineapple Firmware | 31/3/2017 | 17/6/2026 | Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. | |
| Modificada | Media (5.6) | 0.78% | — | Ntt-bp Japan Connected-free Wi-fi | 19/6/2016 | 17/6/2026 | The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Ntt-bp Japan Connected-free Wi-fi | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID. | |
| Modificada | Media (6.8) | 1.1% | — | Ntt-bp Japan Connected-free Wi-fi | 11/9/2015 | 17/6/2026 | The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors. | |
| Modificada | Alta (9) | 4.8% | — | Belkin N300 Dual-band Wi-fi Range Extender Firmware | 13/8/2015 | 17/6/2026 | Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS… | |
| Modificada | Baja (3.3) | 0.73% | — | Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+9 | 17/6/2013 | 16/6/2026 | SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the… |