Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause a system denial of service. | |
| Modificada | Crítica (9.8) | 1.8% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to leak memory. | |
| Modificada | Alta (7.5) | 1.1% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | Source-routed IPv4 packets were disabled by default. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. Source-routed IPv4 packets may be unexpectedly accepted. | |
| Modificada | Crítica (9.8) | 2.7% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | The issue was addressed with improved data deletion. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A base station factory reset may not delete all user information. | |
| Modificada | Crítica (9.8) | 2.7% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a privileged position may be able to perform a denial of service attack. | |
| Modificada | Media (6.1) | 0.83% | — | Adcon Telemetry A850 Telemetry Gateway Base Station Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Adcon Telemetry A850 Telemetry Gateway Base Station. The Web Interface does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output; this could allow for cross-site scripting. | |
| Modificada | Alta (8.1) | 4.1% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain… | |
| Modificada | Crítica (9.8) | 5.2% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory… | |
| Modificada | Crítica (9.8) | 3.9% | — | Apple Airport Base Station Firmware | 3/7/2016 | 17/6/2026 | Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.8% | — | Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+1 | 26/6/2016 | 17/6/2026 | The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.5% | — | Apple Iphone OSApple MAC OS XApple WatchosApple Airport Base Station Firmware+1 | 26/6/2016 | 17/6/2026 | Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function. | |
| Modificada | Alta (8.6) | 2.2% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors. | |
| Modificada | Alta (8.6) | 1.5% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (8.7) | 1.3% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support. | |
| Modificada | Crítica (10) | 2.5% | — | Adcon A840 Telemetry Gateway Base Station Firmware | 24/12/2015 | 17/6/2026 | Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors. | |
| Modificada | Media (5.4) | 1.1% | — | Apple Airport Base Station Firmware | 8/9/2013 | 16/6/2026 | Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame. | |
| Modificada | Alta (7.1) | 1.4% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write… | |
| Modificada | Media (6.1) | 0.82% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and… | |
| Modificada | Alta (7.5) | 1.8% | — | Airspan Base Station Distribution Unit | 28/3/2008 | 16/6/2026 | Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain administrative access via a telnet login, a different vulnerability than CVE-2008-1262. | |
| Modificada | Media (4.3) | 1.5% | — | Apple Airport Extreme Base Station | 20/3/2008 | 16/6/2026 | Unspecified vulnerability in Apple AirPort Extreme Base Station Firmware 7.3.1 allows remote attackers to cause a denial of service (file sharing hang) via a crafted AFP request, related to "input validation." | |
| Modificada | Media (5) | 2.3% | — | Roger Wilco Base StationAIGamespy Roger WilcoAI | 31/12/2004 | 16/6/2026 | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. | |
| Modificada | Media (5) | 15% | — | Microsoft Mn-500 Wireless Base Station | 6/12/2004 | 16/6/2026 | The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections. |