Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Aplazada | Alta (7.5) | 0.40% | — | HPE Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets. | |
| Aplazada | Crítica (9.8) | 1.1% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | |
| Aplazada | Alta (7.2) | 1.5% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user. | |
| Aplazada | Alta (8.4) | 0.49% | — | Arista Wireless Access PointsAI | 27/6/2024 | 17/6/2026 | This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,… | |
| Aplazada | Media (4.3) | 0.20% | — | Octolize Woocommerce UPS Shipping Live Rates AND Access PointsAI | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This issue affects WooCommerce UPS Shipping – Live Rates and Access Points: from n/a through 2.2.4. | |
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Aplazada | Alta (7.5) | 0.52% | — | UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI | 20/2/2024 | 17/6/2026 | A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi… | |
| Modificada | Crítica (9.8) | 4.4% | — | Zyxel ZLDZyxel Access Points Firmware | 27/11/2020 | 17/6/2026 | A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet. | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller SoftwareCisco Business Access PointsCisco Access Points+1 | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication… | |
| Modificada | Alta (7.4) | 0.49% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.5) | 0.50% | — | Cisco Aironet 1542i FirmwareCisco Aironet 1542d FirmwareCisco Aironet 1562i FirmwareCisco Aironet 1562e Firmware+13 | 15/4/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Alta (7.4) | 0.80% | — | Cisco Aironet 3700e FirmwareCisco Aironet 3700i FirmwareCisco Aironet 3700p FirmwareCisco Access Points | 17/7/2019 | 17/6/2026 | A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client… | |
| Modificada | Alta (7.5) | 0.64% | — | Arubanetworks ArubaosArubanetworks 203rp FirmwareArubanetworks 203r FirmwareArubanetworks Ap-300 Series Access Points Firmware+1 | 7/12/2018 | 17/6/2026 | A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable… | |
| Modificada | Alta (7.4) | 0.86% | — | Cisco Access Points | 17/10/2018 | 17/6/2026 | A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming… | |
| Modificada | Media (6.8) | 0.52% | — | Cisco Aironet Access Points | 17/10/2018 | 17/6/2026 | A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Small Business Wireless Access Points Firmware | 17/2/2016 | 17/6/2026 | Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457. |