Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

131 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.44%—Philips Taolight Smart Wi-fi WIZ Connected LED Bulb 9290022656 Firmware14/11/201917/6/2026
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is…
ModificadaAlta (8.8)0.62%—Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+914/11/201917/6/2026
Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via adjacent access.
ModificadaAlta (7.8)0.36%—Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+914/11/201917/6/2026
Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.
ModificadaCrítica (9.8)2.4%—Autopi Wi-fi/nb FirmwareAutopi 4g/lte Firmware14/10/201917/6/2026
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash function output (input is only 8 characters),…
ModificadaMedia (6.5)1.4%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely…
ModificadaAlta (7.1)1.6%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and…
ModificadaMedia (5.9)2.0%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi…
ModificadaAlta (7.5)1.4%—Qacctv Jooan Ja-q1h Wi-fi Camera Firmware10/12/201817/6/2026
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.
ModificadaAlta (7.5)1.5%—Qacctv Jooan Ja-q1h Wi-fi Camera Firmware10/12/201817/6/2026
Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method.
ModificadaMedia (6.7)0.42%—Supermicro X11ssz FirmwareSupermicro X11ssv FirmwareSupermicro X11ssql FirmwareSupermicro X11ssq Firmware+1069/7/201817/6/2026
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
ModificadaAlta (8.8)0.90%—Vgate Icar 2 Wi-fi Obd2 Firmware30/5/201817/6/2026
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed,…
ModificadaMedia (6.5)0.47%—Vgate Icar 2 Wi-fi Obd2 Firmware30/5/201817/6/2026
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public.
ModificadaAlta (8.8)0.51%—Vgate Icar 2 Wi-fi Obd2 Firmware30/5/201817/6/2026
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication.
ModificadaMedia (6.1)0.77%—Rletech Wi-mgr FirmwareRletech Fds-wi Firmware21/2/201817/6/2026
An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
ModificadaCrítica (9.8)2.3%—Nttdocomo Wi-fi Station L-02f Firmware13/11/201717/6/2026
Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)1.6%—Nttdocomo Wi-fi Station L-02f Firmware15/9/201717/6/2026
Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.
ModificadaCrítica (9.8)2.8%—Nttdocomo Wi-fi Station L-02f Firmware15/9/201717/6/2026
Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.
ModificadaCrítica (9.8)64%💥 ExploitBroadcom Bcm43xx Wi-fi Chipset Firmware4/6/201717/6/2026
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
ModificadaAlta (8.8)2.0%—Broadcom Hardmac Wi-fi SOC Firmware5/4/201717/6/2026
On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition Information Element (FT-IE).
ModificadaAlta (7.5)37%💥 ExploitHak5 Wi-fi Pineapple Firmware31/3/201717/6/2026
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
ModificadaMedia (5.6)0.78%—Ntt-bp Japan Connected-free Wi-fi19/6/201617/6/2026
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
ModificadaMedia (4.3)1.2%—Ntt-bp Japan Connected-free Wi-fi11/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID.
ModificadaMedia (6.8)1.1%—Ntt-bp Japan Connected-free Wi-fi11/9/201517/6/2026
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
ModificadaAlta (9)4.8%—Belkin N300 Dual-band Wi-fi Range Extender Firmware13/8/201517/6/2026
Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS…
ModificadaBaja (3.3)0.73%—Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+917/6/201316/6/2026
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the…