Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.31% | — | Italy Wireless Mini Router Wireless-n 300mAI | 30/10/2025 | 17/6/2026 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password. | |
| Aplazada | Alta (7.5) | 0.33% | — | Eachitaly Wireless-n 300mAI | 30/10/2025 | 17/6/2026 | Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request. | |
| Aplazada | Media (4.9) | 0.15% | — | Codeless Slider TemplatesAI | 27/10/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Request Forgery.This issue affects Slider Templates: from n/a through <= 1.0.3. | |
| Aplazada | Crítica (9.8) | 0.79% | 💥 PoC | Ownid Passwordless LoginAI | 15/10/2025 | 17/6/2026 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.3) | 0.37% | 💥 PoC | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and… | |
| Aplazada | Media (6.5) | 0.21% | 💥 PoC | Eachitaly Wireless Mini RouterAI | 29/9/2025 | 17/6/2026 | Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands. | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Alta (8.8) | 0.18% | — | Megatek Azora Wireless Network ManagementAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Sophos AP6 Series Wireless Access PointAI | 9/9/2025 | 17/6/2026 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7). | |
| Analizada | Media (5.4) | 0.39% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4. | |
| Analizada | Media (5.3) | 0.43% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4. | |
| Analizada | Media (5.4) | 0.39% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4. | |
| Aplazada | Alta (7.1) | 0.21% | — | Intel Proset Wireless Wifi SoftwareAI | 12/8/2025 | 17/6/2026 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.110.0.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Alta (7.2) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format… | |
| Analizada | Crítica (9.1) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute… | |
| Analizada | Crítica (9.8) | 1.3% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted… | |
| Analizada | Crítica (9.8) | 1.00% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated… | |
| Analizada | Media (6.3) | 0.37% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same… | |
| Analizada | Media (5.3) | 0.53% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable… | |
| Analizada | Crítica (9.1) | 0.83% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary… | |
| Analizada | Alta (8.8) | 0.51% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the… | |
| Aplazada | Alta (8.2) | 0.52% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in incorrect handling of packets leading to remote code… | |
| Aplazada | Crítica (9.4) | 0.76% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in a failure during subtraction allowing remote code… | |
| Aplazada | Media (6.5) | 0.25% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect… | |
| Aplazada | Alta (8.6) | 0.47% | — | Honeywell Experion PKSAIHoneywell Onewireless WDMAI | 10/7/2025 | 17/6/2026 | The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code… |