Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.56% | — | Hanwhavision Wave Server SoftwareHanwhavision Pno-a6081r-e1t FirmwareHanwhavision Pno-a6081r-e2t Firmware | 13/11/2023 | 17/6/2026 | Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware… | |
| Modificada | Media (6.5) | 0.44% | — | Arubanetworks Airwave | 17/10/2023 | 17/6/2026 | A vulnerability exists which allows an authenticated attacker to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the attacker to gain access to some data that could be further exploited to laterally access devices managed and monitored by… | |
| Modificada | Alta (7.8) | 0.16% | — | Nokia Wavelite Metro 200 AND FAN FirmwareNokia Wavelite Metro 200 OPS AND Fans FirmwareNokia Wavelite Metro 200 AND F2B Fans FirmwareNokia Wavelite Metro 200 OPS AND F2B Fans Firmware+2 | 4/10/2023 | 17/6/2026 | If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro… | |
| Modificada | Crítica (9.8) | 2.8% | 💥 PoC | Wave-ai Wave | 11/9/2023 | 17/6/2026 | The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't… | |
| Modificada | Alta (7.2) | 0.85% | — | Arubanetworks AirwaveHP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. | |
| Modificada | Alta (7.2) | 1.2% | — | Arubanetworks AirwaveHP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users. | |
| Modificada | Alta (8.8) | 0.38% | — | HP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. | |
| Modificada | Media (6.1) | 0.42% | — | HP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator. | |
| Modificada | Alta (7.8) | 0.95% | — | Wavekeyboard Wave Animated Keyboard Emoji | 30/5/2023 | 17/6/2026 | An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files. | |
| Modificada | Media (5.5) | 0.34% | — | Wavekeyboard Wave Animated Keyboard Emoji | 30/5/2023 | 17/6/2026 | An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files. | |
| Modificada | Alta (7.5) | 0.89% | 💥 PoC | Ieee 802.11Sonicwall Tz670 FirmwareSonicwall Tz570 FirmwareSonicwall Tz570p Firmware+26 | 15/4/2023 | 17/6/2026 | The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or… | |
| Modificada | Media (6.5) | 0.80% | — | Korenix Jetwave 2212g FirmwareKorenix Jetwave 2212x FirmwareKorenix Jetwave 2212s FirmwareKorenix Jetwave 2211c Firmware+11 | 23/2/2023 | 17/6/2026 | Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault. | |
| Modificada | Alta (8.8) | 3.8% | — | Korenix Jetwave 2212g FirmwareKorenix Jetwave 2212x FirmwareKorenix Jetwave 2212s FirmwareKorenix Jetwave 2211c Firmware+11 | 23/2/2023 | 17/6/2026 | Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root. | |
| Modificada | Alta (8.8) | 2.7% | — | Korenix Jetwave 2212g FirmwareKorenix Jetwave 2212x FirmwareKorenix Jetwave 2212s FirmwareKorenix Jetwave 2211c Firmware+11 | 23/2/2023 | 17/6/2026 | Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root. | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Wpwave Hide MY WP | 6/2/2023 | 17/6/2026 | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Alta (7.5) | 0.91% | — | Trustwave ModsecurityDebian Linux | 20/1/2023 | 17/6/2026 | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection. | |
| Modificada | Alta (7.5) | 1.2% | — | Owasp ModsecurityTrustwave ModsecurityDebian Linux | 20/1/2023 | 17/6/2026 | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase. | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Alta (7.8) | 0.18% | — | Emerson Controlwave PAC FirmwareEmerson Controlwave Micro Firmware | 17/8/2022 | 17/6/2026 | The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in… | |
| Modificada | Crítica (9.8) | 16% | — | Filewave | 25/7/2022 | 17/6/2026 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform. | |
| Modificada | Alta (7.5) | 11% | — | Filewave | 25/7/2022 | 17/6/2026 | A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests. | |
| Modificada | Alta (7.5) | 3.7% | 💥 PoC | Netwavepr Indoor IP Camera FirmwareNetwavepr Outdoor IP Camera Firmware | 10/6/2022 | 17/6/2026 | There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password). | |
| Modificada | Alta (8.8) | 2.3% | — | Korenix Jetwave 2212s FirmwareKorenix Jetwave 2212g FirmwareKorenix Jetwave 2311 FirmwareKorenix Jetwave 3220 Firmware+2 | 6/2/2022 | 17/6/2026 | Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31. |