Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

1791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.13%—WiresharkAI29/9/202629/9/2026
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.13%—WiresharkAI29/9/202629/9/2026
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.15%—WiresharkAI29/9/202629/9/2026
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (4.7)0.13%—WiresharkAI29/9/202629/9/2026
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.16%—WiresharkAI29/9/202629/9/2026
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—WiresharkAI29/9/202629/9/2026
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
Pendiente de análisisAlta (8.1)0.39%—WiresharkAI29/9/202629/9/2026
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisMedia (5.5)0.14%—Wireshark SharkdAI29/9/202629/9/2026
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisAlta (8.1)0.36%—WiresharkAI29/9/202629/9/2026
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisAlta (7.5)0.58%—WireAI23/9/202630/9/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the…
AplazadaAlta (7.8)0.19%—Crosswire XiphosAI21/9/202622/9/2026
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
AplazadaMedia (4.3)0.36%—Wireguard Wg-portalAI17/9/202624/9/2026
WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every…
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisAlta (7.5)0.82%—Square WireAI16/9/202630/9/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin,…
AplazadaAlta (8.6)0.63%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
AplazadaMedia (4.8)0.24%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)1.9%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (4.8)0.24%—Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (7.5)0.50%—Signalwire LibksAI11/9/202630/9/2026
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."…
Pendiente de análisisMedia (5.3)0.16%—Sierrawireless Hl78xxAI10/9/202610/9/2026
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first…
AplazadaMedia (5.1)0.68%—LaravelAILaravel LivewireAI31/8/20269/9/2026
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path segments and creates inherited objects.…