Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
1791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.13% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.13% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (4.7) | 0.13% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Wireshark SharkdAI | 29/9/2026 | 29/9/2026 | Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Alta (8.1) | 0.36% | — | WiresharkAI | 29/9/2026 | 29/9/2026 | SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Alta (7.5) | 0.58% | — | WireAI | 23/9/2026 | 30/9/2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the… | |
| Aplazada | Alta (7.8) | 0.19% | — | Crosswire XiphosAI | 21/9/2026 | 22/9/2026 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | |
| Aplazada | Media (4.3) | 0.36% | — | Wireguard Wg-portalAI | 17/9/2026 | 24/9/2026 | WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every… | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Pendiente de análisis | Alta (7.5) | 0.82% | — | Square WireAI | 16/9/2026 | 30/9/2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin,… | |
| Aplazada | Alta (8.6) | 0.63% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (7.5) | 0.50% | — | Signalwire LibksAI | 11/9/2026 | 30/9/2026 | libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."… | |
| Pendiente de análisis | Media (5.3) | 0.16% | — | Sierrawireless Hl78xxAI | 10/9/2026 | 10/9/2026 | The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first… | |
| Aplazada | Media (5.1) | 0.68% | — | LaravelAILaravel LivewireAI | 31/8/2026 | 9/9/2026 | Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path segments and creates inherited objects.… |