Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)7.3%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.
ModificadaAlta (7.5)1.5%—Belkin 54G Wireless Router26/7/200516/6/2026
Los rúter inalámbricos Belkin 54g no fijan adecuadamente el password de administración, lo que permite que atacantes remotos ganen acceso mediante las interfaces de administración de Telnet o de web.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)1.4%—Belkin 54G Wireless Router2/5/200516/6/2026
Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.
ModificadaAlta (7.5)2.3%—Crosswire Bible Society Sword2/5/200516/6/2026
diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaMedia (5)1.2%—Belkin 54G Wireless Router2/5/200516/6/2026
The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.
ModificadaMedia (5)1.8%—Limewire14/3/200516/6/2026
Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.
ModificadaMedia (5)6.9%💥 ExploitLimewire14/3/200516/6/2026
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.
ModificadaAlta (7.2)0.48%—Firewire Ieee1/3/200516/6/2026
A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit. NOTE: this was reported in…
ModificadaBaja (2.1)0.33%—Checkpoint Check Point Integrity ClientZonelabs ZonealarmZonelabs Zonealarm Wireless Security11/2/200516/6/2026
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause…
ModificadaAlta (7.5)1.4%💥 ExploitIP3 Networks IP3 NetaccessIP3 Networks IP3 Netaccess - HospitalityIP3 Networks IP3 Netaccess - Wireless Hotspots31/12/200416/6/2026
SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.
ModificadaAlta (7.5)1.7%—Sweex Wireless Broadband Router Accesspoint 802.11g31/12/200416/6/2026
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
ModificadaMedia (4.3)2.3%💥 Exploit2wire Homeportal31/12/200416/6/2026
Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.
ModificadaMedia (6.4)1.7%—Zonet Zsr1104we Wireless Router Runtime Code31/12/200416/6/2026
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.
ModificadaMedia (5)15%—Microsoft Mn-500 Wireless Base Station6/12/200416/6/2026
El interfaz de administración Web de Microsoft MN-500 Wireless Router permite a atacantes remotos causar una denegación de servicio (rechazo de conexión) mediante un número largo de conexiones HTTP.
ModificadaMedia (5)3.0%💥 ExploitBT Voyager 2000 Wireless Adsl Router6/12/200416/6/2026
El encaminador ADSL inalámbrico BT Voyager 2000 tiene un nombre de comunidad SNMP público por defecto, lo que permite a atacantes remotos obtener información sensible, como la contraseña, que se almacena en texto claro.
ModificadaAlta (7.2)0.37%—Tripwire6/8/200416/6/2026
Vulnerabildad de cadena de formato en Tripwire commercial 4.0.1 y anteriores, incluyendo 2.4, y open source 2.3.1 y anteriores permite a usuarios locales ganar privilegios mediante especificadores de cadena de formato en el nombre del ficheros, que es usado para la generación de un informe de correo electrónico.
ModificadaAlta (7.5)1.5%—Wire Plastic Design Wpquiz30/7/200416/6/2026
WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.
ModificadaMedia (5)2.3%—Ieee 802.11 Wireless Protocol7/7/200416/6/2026
El algoritmo de identificicación de canal vacio (Clear Channel Assessment - CCA) en el protocolo inalámbrico IEEE 802.11, cuando usa codificación de trasmisión de codificación DSSS, permite a atacantes remotos causar una denegación de servicio mediante ciertas señales de RF que causan que el canel aparezca ocupado…
ModificadaAlta (10)4.6%—Cisco Wireless LAN Solution EngineCisco Hosting Solution Engine1/6/200416/6/2026
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.
ModificadaAlta (7.5)3.8%—Nortel Business Communications ManagerNortel 802.11 Wireless IP GatewayNortel Succession Communication Server 100017/2/200416/6/2026
Múltiples vulnerabilidades en la implementación del protocolo H.323 en Nortel Networks Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, y 802.11 Wireless IP Gateway permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario, como se demostró…
ModificadaMedia (4.6)1.3%—Microsoft Mn-500 Wireless Base Station31/12/200316/6/2026
The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.
ModificadaMedia (5)1.6%—D-link Di-614+Longshine Technologie Longshine Wireless Ethernet Access Point31/12/200316/6/2026
TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication.
ModificadaAlta (7.2)1.3%💥 ExploitWireless Tools Project Wireless Tools15/12/200316/6/2026
Desbordamiento de búfer en iwconfig (cuando tiene instalado un setuid ) permite que usuarios locales ejecuten código arbitrario mediante una variable de entorno OUT muy larga.
ModificadaAlta (7.2)1.1%💥 ExploitWireless Tools15/12/200316/6/2026
Desbordamiento de búfer en iwconfig permite que usuarios locales ejecuten código arbitrario mediante una variable de entorno HOME demasiado larga.