Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.24% | — | Motorola Smartphone Firmware | 1/9/2023 | 17/6/2026 | I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This… | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Webex Room Phone FirmwareCisco Webex Share FirmwareCisco SIP IP Phone Software | 20/1/2023 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient resource allocation. An attacker… | |
| Modificada | Alta (7.2) | 1.3% | — | Innovaphone Firmware | 30/9/2022 | 17/6/2026 | AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. | |
| Modificada | Alta (7.5) | 8.0% | — | Cisco IP Dect 210 FirmwareCisco IP Dect 6825 FirmwareCisco IP Phone 8811 FirmwareCisco IP Phone 8841 Firmware+4 | 6/11/2020 | 17/6/2026 | A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker… | |
| Modificada | Alta (7.5) | 2.0% | — | Essential Phone Firmware | 25/4/2019 | 17/6/2026 | The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-installed platform app with a package name of com.ts.android.hiddenmenu (versionName=1.0, platformBuildVersionName=8.1.0) that contains an exported activity app component named… | |
| Modificada | Alta (8.8) | 7.6% | — | Audiocodes 420hd IP Phone Firmware | 1/4/2019 | 17/6/2026 | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via… | |
| Modificada | Alta (8.8) | 68% | 💥 Exploit | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution. | |
| Modificada | Media (4.8) | 0.77% | — | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS. | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Unified IP Phone FirmwareCisco IP Phone Firmware | 7/6/2018 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco IP Phone Firmware | 7/6/2018 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS)… | |
| Modificada | Media (5.5) | 0.65% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access… | |
| Modificada | Media (5.5) | 0.65% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access… | |
| Modificada | Media (6.1) | 0.52% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter and cause to memory out-of-bound read. | |
| Modificada | Alta (7.8) | 0.64% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a arbitrary memory write vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific… | |
| Modificada | Alta (7.8) | 0.64% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter… | |
| Modificada | Alta (7.8) | 0.81% | — | Huawei MTK Platform Smart Phone Firmware | 22/11/2017 | 17/6/2026 | The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Small Business IP Phone Firmware | 19/10/2017 | 17/6/2026 | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the… | |
| Modificada | Alta (7.8) | 0.89% | — | Huawei P8 Smartphone Firmware | 2/8/2016 | 17/6/2026 | Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192. | |
| Modificada | Alta (7.3) | 0.84% | — | Huawei P8 Smartphone Firmware | 2/8/2016 | 17/6/2026 | Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Yealink Voip Phone Firmware | 16/7/2014 | 17/6/2026 | CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet. | |
| Modificada | Media (4.3) | 1.9% | — | Yealink Voip Phone FirmwareYealink Voip Phone | 16/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet. | |
| Modificada | Media (6.6) | 0.28% | — | Cisco Unified IP Phone FirmwareCisco Unified IP Phone 8961Cisco Unified IP Phone 9951Cisco Unified IP Phone 9971 | 13/11/2013 | 17/6/2026 | The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382. | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco Unified IP Phone 8945Cisco Unified IP Phone Firmware | 29/8/2013 | 16/6/2026 | The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+14 | 13/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,… | |
| Modificada | Alta (7.1) | 3.2% | — | Linux KernelAvaya 96x1 IP Deskphone Firmware | 17/5/2012 | 16/6/2026 | The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device. |