Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.63%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
AplazadaMedia (4.8)0.24%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)1.9%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.24%—Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (7.2)0.24%—Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+1217/6/202617/6/2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump…
AplazadaMedia (5.1)0.29%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
AplazadaMedia (5.1)0.33%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
AplazadaMedia (4.8)0.25%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
AplazadaCrítica (9.3)2.3%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.
AplazadaCrítica (9.3)0.72%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.
AplazadaMedia (6.9)0.12%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
AplazadaMedia (5.1)0.15%—Elecom Wireless LANAI3/2/202617/6/2026
Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.
AplazadaAlta (8.5)0.15%—Realtek Wireless LAN UtilityAI21/1/202617/6/2026
Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or…
AplazadaAlta (7.4)0.25%—Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI7/5/202517/6/2026
A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This…
AplazadaMedia (5.7)0.60%—Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI10/9/202417/6/2026
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
AplazadaMedia (6.8)0.85%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.
AplazadaMedia (6.8)0.36%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
AplazadaMedia (4.3)0.25%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.
AplazadaAlta (7.1)0.69%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product.
AnalizadaAlta (7.4)0.29%—Cisco Wireless LAN Controller SoftwareCisco IOS XE27/3/202417/6/2026
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed…
AnalizadaAlta (8.6)0.63%—Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software27/3/202417/6/2026
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this…
ModificadaMedia (4.7)0.26%—Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware27/9/202317/6/2026
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A…
Orbitaley — Vulnerabilidades