Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.31%—Italy Wireless Mini Router Wireless-n 300mAI30/10/202517/6/2026
Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.
AplazadaAlta (7.5)0.33%—Eachitaly Wireless-n 300mAI30/10/202517/6/2026
Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.
AplazadaMedia (4.9)0.15%—Codeless Slider TemplatesAI27/10/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Request Forgery.This issue affects Slider Templates: from n/a through <= 1.0.3.
AplazadaCrítica (9.8)0.79%💥 PoCOwnid Passwordless LoginAI15/10/202517/6/2026
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.3)0.37%💥 PoCRekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+130/9/202517/6/2026
serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and…
AplazadaMedia (6.5)0.21%💥 PoCEachitaly Wireless Mini RouterAI29/9/202517/6/2026
Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.
AplazadaMedia (4.3)0.12%—Cisco Wireless Access Point SoftwareAI24/9/202525/9/2026
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action…
AplazadaAlta (8.8)0.18%—Megatek Azora Wireless Network ManagementAI16/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the…
AplazadaCrítica (9.8)0.88%—Sophos AP6 Series Wireless Access PointAI9/9/202517/6/2026
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
AnalizadaMedia (5.4)0.39%—Namelessmc Nameless18/8/202517/6/2026
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.
AnalizadaMedia (5.3)0.43%—Namelessmc Nameless18/8/202517/6/2026
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.
AnalizadaMedia (5.4)0.39%—Namelessmc Nameless18/8/202517/6/2026
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4.
AplazadaAlta (7.1)0.21%—Intel Proset Wireless Wifi SoftwareAI12/8/202517/6/2026
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.110.0.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AnalizadaAlta (7.2)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format…
AnalizadaCrítica (9.1)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute…
AnalizadaCrítica (9.8)1.3%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted…
AnalizadaCrítica (9.8)1.00%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated…
AnalizadaMedia (6.3)0.37%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same…
AnalizadaMedia (5.3)0.53%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable…
AnalizadaCrítica (9.1)0.83%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary…
AnalizadaAlta (8.8)0.51%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the…
AplazadaAlta (8.2)0.52%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in incorrect handling of packets leading to remote code…
AplazadaCrítica (9.4)0.76%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in a failure during subtraction allowing remote code…
AplazadaMedia (6.5)0.25%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect…
AplazadaAlta (8.6)0.47%—Honeywell Experion PKSAIHoneywell Onewireless WDMAI10/7/202517/6/2026
The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code…
Orbitaley — Vulnerabilidades