Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.30%—Garmin Empirbus Wireless Display Unit Firmware13/5/202617/6/2026
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all…
AnalizadaMedia (5)0.14%—Garmin Empirbus Wireless Display Unit Firmware13/5/202617/6/2026
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary JavaScript code within the context of the WDU webpage. Full administrator level access to the device is possible. To…
AnalizadaCrítica (9.3)0.14%—Garmin Empirbus Wireless Display Unit Firmware13/5/202617/6/2026
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this…
AnalizadaAlta (7.5)0.39%—Garmin Empirbus Wireless Display Unit Firmware13/5/202617/6/2026
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesystem is enabled.…
AplazadaMedia (5.1)0.29%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
AplazadaMedia (5.1)0.33%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
AplazadaMedia (4.8)0.25%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
AplazadaCrítica (9.3)2.3%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.
AplazadaCrítica (9.3)0.72%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.
AplazadaMedia (6.9)0.12%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
ModificadaMedia (6.8)0.36%—Bx33661 Wireshark MCP11/5/202617/6/2026
Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_export_objects MCP tool that accepts an attacker-controlled dest_dir parameter and passes it to tshark's --export-objects…
AplazadaMedia (5.5)2.1%—A-g-u-p-t-a Wireshark-mcpAI5/5/202617/6/2026
A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has…
AnalizadaAlta (7.8)0.07%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/20267/10/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AnalizadaMedia (5.5)0.14%—Wireshark2/5/202617/6/2026
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
ModificadaAlta (7.8)0.18%—Wireshark1/5/202615/7/2026
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
ModificadaAlta (7.8)0.19%—Wireshark1/5/202615/7/2026
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
AnalizadaMedia (5.5)0.14%—Wireshark1/5/202617/6/2026
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
ModificadaAlta (7.8)0.19%—Wireshark1/5/202615/7/2026
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
AnalizadaMedia (5.5)0.14%—Wireshark30/4/202617/6/2026
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.14%—Wireshark30/4/202617/6/2026
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.14%—Wireshark30/4/202617/6/2026
SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.16%—Wireshark30/4/202617/6/2026
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.16%—Wireshark30/4/202617/6/2026
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.16%—Wireshark30/4/202617/6/2026
DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
Orbitaley — Vulnerabilidades