Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1800 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.55%—Wgportal Wireguard Portal26/2/202617/6/2026
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and…
AnalizadaAlta (7.5)0.26%—Wireshark25/2/202617/6/2026
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
AnalizadaAlta (7.5)0.26%—Wireshark25/2/202617/6/2026
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
AnalizadaAlta (7.5)0.27%—Wireshark25/2/202617/6/2026
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
AplazadaMedia (6.7)0.32%—Hotwired TurboAI11/2/202617/6/2026
BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.
AplazadaMedia (5.3)0.20%—Wired Impact Volunteer ManagementAI3/2/202617/6/2026
Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.
AplazadaMedia (5.1)0.15%—Elecom Wireless LANAI3/2/202617/6/2026
Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.
AplazadaAlta (8.5)0.14%—Hotwired TurboAI1/2/202617/6/2026
BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.
AplazadaAlta (7.2)0.91%💥 PoCHikvision Wireless Access PointAI30/1/202617/6/2026
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
AplazadaAlta (8.5)0.15%—Realtek Wireless LAN UtilityAI21/1/202617/6/2026
Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or…
AplazadaMedia (5.3)0.37%—Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI21/1/202617/6/2026
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by…
AnalizadaMedia (4.8)0.28%—Hotwired Turbo20/1/202617/6/2026
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests based on sequence or timing) or by…
AnalizadaCrítica (9.8)0.64%—Livewire-filemanager Filemanager16/1/202617/6/2026
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel…
AnalizadaMedia (5.4)0.27%—Eachitaly Wireless Mini Router Wireless-n 300m Firmware15/1/202617/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm.
AnalizadaMedia (6.5)0.25%—Wireshark14/1/202617/6/2026
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
AnalizadaMedia (6.5)0.21%—Wireshark14/1/202617/6/2026
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
AnalizadaMedia (5.5)0.14%—Wireshark14/1/202617/6/2026
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
AnalizadaMedia (6.5)0.21%—Wireshark14/1/202617/6/2026
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
AplazadaAlta (8.8)0.46%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session…
AplazadaAlta (8.8)0.38%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this…
AnalizadaCrítica (9.1)0.71%—Pandawireless Pwru01 Firmware8/1/202617/6/2026
An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege…
AplazadaAlta (8.7)0.30%—Nucom 11N Wireless RouterAI31/12/202517/6/2026
NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode…
AplazadaMedia (5.3)0.21%—Woo-reviews-by-wiremoAI31/12/202517/6/2026
Missing Authorization vulnerability in Wiremo Wiremo woo-reviews-by-wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through <= 1.4.99.