Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+181 | 8/7/2025 | 17/6/2026 | Transient DOS may occur while processing malformed length field in SSID IEs. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 FirmwareQualcomm Immersive Home 216 Firmware+236 | 8/7/2025 | 17/6/2026 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+271 | 8/7/2025 | 17/6/2026 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+242 | 8/7/2025 | 17/6/2026 | Memory corruption while retrieving the CBOR data from TA. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+217 | 8/7/2025 | 17/6/2026 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+185 | 8/7/2025 | 17/6/2026 | Memory corruption while operating the mailbox in Automotive. | |
| Aplazada | Media (6.3) | 0.30% | — | ABB Rmc-100AIABB Rmc-100 LiteAI | 3/7/2025 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration data. This issue affects… | |
| Aplazada | Alta (8.2) | 0.42% | — | ABB Rmc-100AIABB Rmc-100 LiteAI | 3/7/2025 | 17/6/2026 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer for username or… | |
| Aplazada | Alta (8.2) | 0.40% | — | ABB Rmc-100AIABB Rmc-100 LiteAI | 3/7/2025 | 17/6/2026 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects… | |
| Aplazada | Media (6.3) | 0.28% | — | ABB Rmc-100AIABB Rmc-100 LiteAI | 3/7/2025 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016. | |
| Aplazada | Media (6.8) | 0.19% | — | ABB Lite Panel PROAI | 30/6/2025 | 17/6/2026 | Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1. | |
| Aplazada | Alta (8.6) | 0.42% | — | Mediawiki TabberneueAI | 27/6/2025 | 17/6/2026 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload into any allowed attribute of the `<tabber>` tag. Version 3.1.1 contains a patch for the bug. | |
| Analizada | Media (6.7) | 0.21% | — | Broadcom Rabbitmq Server | 19/6/2025 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded… | |
| Aplazada | Media (6.5) | 0.20% | — | Ryan Burnette Abbie ExpanderAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Abbie Expander abbie-expander allows Stored XSS.This issue affects Abbie Expander: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.9) | 0.49% | — | Gowabby HfishAI | 27/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The manipulation of the argument r leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (7.1) | 0.22% | — | Andreyk Remote Images GrabberAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyk Remote Images Grabber remote-images-grabber allows Reflected XSS.This issue affects Remote Images Grabber: from n/a through <= 0.6. | |
| Modificada | Media (5.4) | 0.39% | — | Phpjabbers Cleaning Business Software | 8/5/2025 | 17/6/2026 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters. | |
| Modificada | Media (6.5) | 0.39% | — | Phpjabbers Event Booking Calendar | 8/5/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+36 | 6/5/2025 | 17/6/2026 | Memory corruption while processing escape code, when DisplayId is passed with large unsigned value. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+29 | 6/5/2025 | 17/6/2026 | Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+16 | 6/5/2025 | 17/6/2026 | Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wcd9385 FirmwareQualcomm Wcd9390 FirmwareQualcomm Wcd9395 FirmwareQualcomm Wcn3950 Firmware+142 | 6/5/2025 | 17/6/2026 | Memory corruption during the FRS UDS generation process. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+177 | 6/5/2025 | 17/6/2026 | Memory corruption while triggering commands in the PlayReady Trusted application. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+175 | 6/5/2025 | 17/6/2026 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Snapdragon AR2 GEN 1 FirmwareQualcomm Snapdragon Auto 5G Modem-rf GEN 2 FirmwareQualcomm Snapdragon X24 LTE Modem FirmwareQualcomm Snapdragon X32 5G Modem-rf Firmware+169 | 6/5/2025 | 17/6/2026 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. |