Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.30% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all… | |
| Analizada | Media (5) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary JavaScript code within the context of the WDU webpage. Full administrator level access to the device is possible. To… | |
| Analizada | Crítica (9.3) | 0.14% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this… | |
| Analizada | Alta (7.5) | 0.39% | — | Garmin Empirbus Wireless Display Unit Firmware | 13/5/2026 | 17/6/2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesystem is enabled.… | |
| Aplazada | Media (5.1) | 0.29% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations. | |
| Aplazada | Media (5.1) | 0.33% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken. | |
| Aplazada | Media (4.8) | 0.25% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser. | |
| Aplazada | Crítica (9.3) | 2.3% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed. | |
| Aplazada | Media (6.9) | 0.12% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file. | |
| Modificada | Media (6.8) | 0.36% | — | Bx33661 Wireshark MCP | 11/5/2026 | 17/6/2026 | Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_export_objects MCP tool that accepts an attacker-controlled dest_dir parameter and passes it to tshark's --export-objects… | |
| Aplazada | Media (5.5) | 2.1% | — | A-g-u-p-t-a Wireshark-mcpAI | 5/5/2026 | 17/6/2026 | A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 7/10/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 2/5/2026 | 17/6/2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 | |
| Modificada | Alta (7.8) | 0.18% | — | Wireshark | 1/5/2026 | 15/7/2026 | Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution | |
| Modificada | Alta (7.8) | 0.19% | — | Wireshark | 1/5/2026 | 15/7/2026 | RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 1/5/2026 | 17/6/2026 | K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Modificada | Alta (7.8) | 0.19% | — | Wireshark | 1/5/2026 | 15/7/2026 | SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 30/4/2026 | 17/6/2026 | GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 30/4/2026 | 17/6/2026 | WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 30/4/2026 | 17/6/2026 | SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.16% | — | Wireshark | 30/4/2026 | 17/6/2026 | BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.16% | — | Wireshark | 30/4/2026 | 17/6/2026 | ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.16% | — | Wireshark | 30/4/2026 | 17/6/2026 | DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 |