Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 30/4/2026 | 17/6/2026 | AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Media (5.5) | 0.14% | — | Wireshark | 30/4/2026 | 17/6/2026 | ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Alta (7.5) | 0.19% | — | Wireshark | 30/4/2026 | 17/6/2026 | Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Alta (7.5) | 0.28% | — | Wireshark | 30/4/2026 | 17/6/2026 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Modificada | Alta (7.5) | 0.28% | — | Wireshark | 30/4/2026 | 17/6/2026 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Alta (7.5) | 0.28% | — | Wireshark | 30/4/2026 | 17/6/2026 | UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Analizada | Alta (7.5) | 0.28% | — | Wireshark | 30/4/2026 | 17/6/2026 | HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | |
| Aplazada | Media (5.5) | 2.1% | — | Toowiredd Chatgpt-mcp-serverAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Rechazada | Sin puntuar | — | — | ProcesswireAI | 15/4/2026 | 9/7/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing… | |
| Analizada | Alta (8.8) | 0.28% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 7/10/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Cisco IOS XE Wireless Controller SoftwareAI | 25/3/2026 | 17/6/2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Crítica (9.1) | 0.20% | — | BacnetAIWiresharkAIJohnsoncontrols WebctrlAI | 21/3/2026 | 17/6/2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format… | |
| Aplazada | Baja (1.9) | 1.1% | — | 0xkoda WiremcpAI | 11/3/2026 | 17/6/2026 | A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made… | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Analizada | Alta (8.8) | 0.55% | — | Wgportal Wireguard Portal | 26/2/2026 | 17/6/2026 | WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and… | |
| Analizada | Alta (7.5) | 0.26% | — | Wireshark | 25/2/2026 | 17/6/2026 | RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | |
| Analizada | Alta (7.5) | 0.26% | — | Wireshark | 25/2/2026 | 17/6/2026 | NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service | |
| Analizada | Alta (7.5) | 0.27% | — | Wireshark | 25/2/2026 | 17/6/2026 | USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | |
| Aplazada | Media (6.7) | 0.32% | — | Hotwired TurboAI | 11/2/2026 | 17/6/2026 | BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain. | |
| Aplazada | Media (5.3) | 0.20% | — | Wired Impact Volunteer ManagementAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8. | |
| Aplazada | Media (5.1) | 0.15% | — | Elecom Wireless LANAI | 3/2/2026 | 17/6/2026 | Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed. |