Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.14%—Wireshark30/4/202617/6/2026
AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaMedia (5.5)0.14%—Wireshark30/4/202617/6/2026
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaAlta (7.5)0.19%—Wireshark30/4/202617/6/2026
Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaAlta (7.5)0.28%—Wireshark30/4/202617/6/2026
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
ModificadaAlta (7.5)0.28%—Wireshark30/4/202617/6/2026
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaAlta (7.5)0.28%—Wireshark30/4/202617/6/2026
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AnalizadaAlta (7.5)0.28%—Wireshark30/4/202617/6/2026
HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AplazadaMedia (5.5)2.1%—Toowiredd Chatgpt-mcp-serverAI26/4/202617/6/2026
A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made…
RechazadaSin puntuar——ProcesswireAI15/4/20269/7/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing…
AnalizadaAlta (8.8)0.28%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/20267/10/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Pendiente de análisisAlta (8.6)0.35%—Cisco IOS XE Wireless Controller SoftwareAI25/3/202617/6/2026
A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is…
Pendiente de análisisCrítica (9.1)0.20%—BacnetAIWiresharkAIJohnsoncontrols WebctrlAI21/3/202617/6/2026
Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format…
AplazadaBaja (1.9)1.1%—0xkoda WiremcpAI11/3/202617/6/2026
A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made…
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+392/3/202617/6/2026
Transient DOS when MAC configures config id greater than supported maximum value.
AnalizadaAlta (7.2)0.14%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+2022/3/202617/6/2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
AnalizadaAlta (7.8)0.07%—Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+1742/3/202617/6/2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1212/3/202617/6/2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
AnalizadaAlta (8.8)0.55%—Wgportal Wireguard Portal26/2/202617/6/2026
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and…
AnalizadaAlta (7.5)0.26%—Wireshark25/2/202617/6/2026
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
AnalizadaAlta (7.5)0.26%—Wireshark25/2/202617/6/2026
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
AnalizadaAlta (7.5)0.27%—Wireshark25/2/202617/6/2026
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
AplazadaMedia (6.7)0.32%—Hotwired TurboAI11/2/202617/6/2026
BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.
AplazadaMedia (5.3)0.20%—Wired Impact Volunteer ManagementAI3/2/202617/6/2026
Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.
AplazadaMedia (5.1)0.15%—Elecom Wireless LANAI3/2/202617/6/2026
Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.