Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI | 21/1/2026 | 17/6/2026 | A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by… | |
| Analizada | Media (5.4) | 0.27% | — | Eachitaly Wireless Mini Router Wireless-n 300m Firmware | 15/1/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm. | |
| Aplazada | Alta (8.8) | 0.46% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session… | |
| Aplazada | Alta (8.8) | 0.38% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an… | |
| Aplazada | Media (6.1) | 0.26% | — | Lesson Plan BookAI | 9/1/2026 | 17/6/2026 | The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.7) | 0.12% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting… | |
| Aplazada | Alta (8.7) | 0.12% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this… | |
| Analizada | Crítica (9.1) | 0.71% | — | Pandawireless Pwru01 Firmware | 8/1/2026 | 17/6/2026 | An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege… | |
| Aplazada | Alta (8.7) | 0.30% | — | Nucom 11N Wireless RouterAI | 31/12/2025 | 17/6/2026 | NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode… | |
| Analizada | Alta (7.5) | 2.4% | 💥 PoC | Serverless | 30/12/2025 | 17/6/2026 | The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and prior to version 4.29.3, a command injection vulnerability exists in the Serverless Framework's built-in MCP server package (@serverless/mcp). This vulnerability only… | |
| Aplazada | Media (5.1) | 0.16% | — | Devolo Dlan 500 AV Wireless PlusAI | 24/12/2025 | 17/6/2026 | Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a… | |
| Aplazada | Alta (8.7) | 0.42% | — | Devolo Dlan 500 AV Wireless+AI | 24/12/2025 | 17/6/2026 | devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration… | |
| Aplazada | Media (5.4) | 0.13% | — | Alessandro Piconi Simple Keyword TO LinkAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5. | |
| Analizada | Baja (2.7) | 0.48% | — | Facelessuser Pymdown Extensions | 16/12/2025 | 17/6/2026 | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`). In systems that take unchecked user content, this could cause long hanges when processing the data if a malicious… | |
| Modificada | Alta (7.5) | 0.85% | — | Fearlessgeekmedia Fearlesscms | 10/12/2025 | 17/6/2026 | Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function. | |
| Modificada | Alta (7.5) | 0.85% | — | Fearlessgeekmedia Fearlesscms | 10/12/2025 | 17/6/2026 | Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function. | |
| Modificada | Media (6.1) | 0.26% | — | Fearlessgeekmedia Fearlesscms | 10/12/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component. | |
| Analizada | Media (6.1) | 0.22% | 💥 PoC | Ruckuswireless Ruckus Unleashed | 25/11/2025 | 17/6/2026 | A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp. | |
| Aplazada | Media (5.3) | 0.34% | — | WP Headless CMS FrameworkAI | 13/11/2025 | 17/6/2026 | The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking for the existence of the Authorization header in a request when determining if the nonce protection should be bypassed. This makes it… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (7) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.3) | 0.18% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (5.7) | 0.12% | — | Intel Proset Wireless Wifi SoftwareAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Authorized adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur… |