Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.37%—Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI21/1/202617/6/2026
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by…
AnalizadaMedia (5.4)0.27%—Eachitaly Wireless Mini Router Wireless-n 300m Firmware15/1/202617/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm.
AplazadaAlta (8.8)0.46%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session…
AplazadaAlta (8.8)0.38%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an…
AplazadaMedia (6.1)0.26%—Lesson Plan BookAI9/1/202617/6/2026
The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this…
AnalizadaCrítica (9.1)0.71%—Pandawireless Pwru01 Firmware8/1/202617/6/2026
An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege…
AplazadaAlta (8.7)0.30%—Nucom 11N Wireless RouterAI31/12/202517/6/2026
NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode…
AnalizadaAlta (7.5)2.4%💥 PoCServerless30/12/202517/6/2026
The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and prior to version 4.29.3, a command injection vulnerability exists in the Serverless Framework's built-in MCP server package (@serverless/mcp). This vulnerability only…
AplazadaMedia (5.1)0.16%—Devolo Dlan 500 AV Wireless PlusAI24/12/202517/6/2026
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a…
AplazadaAlta (8.7)0.42%—Devolo Dlan 500 AV Wireless+AI24/12/202517/6/2026
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration…
AplazadaMedia (5.4)0.13%—Alessandro Piconi Simple Keyword TO LinkAI24/12/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5.
AnalizadaBaja (2.7)0.48%—Facelessuser Pymdown Extensions16/12/202517/6/2026
PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`). In systems that take unchecked user content, this could cause long hanges when processing the data if a malicious…
ModificadaAlta (7.5)0.85%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function.
ModificadaAlta (7.5)0.85%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.
ModificadaMedia (6.1)0.26%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.
AnalizadaMedia (6.1)0.22%💥 PoCRuckuswireless Ruckus Unleashed25/11/202517/6/2026
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
AplazadaMedia (5.3)0.34%—WP Headless CMS FrameworkAI13/11/202517/6/2026
The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking for the existence of the Authorization header in a request when determining if the nonce protection should be bypassed. This makes it…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (7)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaAlta (8.3)0.18%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaMedia (5.7)0.12%—Intel Proset Wireless Wifi SoftwareAI11/11/202517/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Authorized adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur…