Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.55% | — | HPE Networking Instant ON Access PointAI | 29/9/2026 | 1/10/2026 | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Watchguard Access PointAI | 28/9/2026 | 28/9/2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.24% | — | Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (5.1) | 0.29% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations. | |
| Aplazada | Media (5.1) | 0.33% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken. | |
| Aplazada | Media (4.8) | 0.25% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser. | |
| Aplazada | Crítica (9.3) | 2.3% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed. | |
| Aplazada | Media (6.9) | 0.12% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file. | |
| Pendiente de análisis | Media (6.9) | 0.46% | — | Ruckus Access PointAI | 26/3/2026 | 17/6/2026 | Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including… | |
| Aplazada | Alta (7.2) | 0.91% | — | Hikvision Wireless Access PointAI | 30/1/2026 | 17/6/2026 | Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Aplazada | Alta (7.5) | 0.40% | — | HPE Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets. | |
| Aplazada | Media (4.3) | 0.17% | — | Cisco Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless… | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Sophos AP6 Series Wireless Access PointAI | 9/9/2025 | 17/6/2026 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7). | |
| Aplazada | Crítica (9.8) | 1.1% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | |
| Aplazada | Alta (7.2) | 1.5% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user. | |
| Aplazada | Alta (7.2) | 1.4% | — | Hikvision Wireless Access PointAI | 13/6/2025 | 17/6/2026 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Crítica (9.8) | 1.4% | — | Aruba Access PointAI | 25/9/2024 | 17/6/2026 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute… | |
| Aplazada | Media (5.3) | 0.21% | — | UI Unifi U6 Access PointAI | 22/7/2024 | 17/6/2026 | A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later. | |
| Aplazada | Media (4.8) | 0.20% | — | UI Unifi IOS APPAIUI Unifi Access PointAI | 9/7/2024 | 17/6/2026 | UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later. |