Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)1.2%—Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+523/12/202417/6/2026
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
ModificadaAlta (7.5)0.92%—ES Iperf3Netapp Ontap 9Netapp HCI Compute Node18/12/202417/6/2026
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca2062 Firmware+162/12/202417/6/2026
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+502/12/202417/6/2026
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2073 Firmware+152/12/202417/6/2026
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+3252/12/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csrb31024 Firmware+2072/12/202417/6/2026
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
AplazadaMedia (5.5)0.37%—Kion Computer Kion Exchange Programs SoftwareAI21/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS. This issue affects KION Exchange Programs Software: before 1.21.9092.29966.
AplazadaMedia (5.1)0.53%—SEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI18/11/202417/6/2026
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
ModificadaMedia (6)0.55%—QemuNetapp HCI Compute Node14/11/202417/6/2026
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of…
AplazadaMedia (5.1)0.42%—ITG Computer Technology Vsrm Supplier Relationship Management SystemAI14/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS, Cross-Site Scripting (XSS). This issue affects vSRM Supplier Relationship Management System: before 28.08.2024.
AnalizadaMedia (4.3)0.77%💥 PoCOretnom23 Computer Laboratory Management System13/11/202417/6/2026
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
ModificadaCrítica (9.8)1.8%💥 PoCWebfulcreations Computer Repair Shop11/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.
AnalizadaAlta (7.8)0.10%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2644/11/202417/6/2026
Memory corruption while processing voice packet with arbitrary data received from ADSP.
AnalizadaAlta (7.8)0.10%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1744/11/202417/6/2026
Memory corruption while handling session errors from firmware.
AnalizadaAlta (7.8)0.10%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+214/11/202417/6/2026
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
AnalizadaAlta (7.8)0.10%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+214/11/202417/6/2026
Memory corruption while station LL statistic handling.
AnalizadaCrítica (9.1)0.14%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2314/11/202417/6/2026
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
AnalizadaAlta (7)0.07%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+404/11/202417/6/2026
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
AnalizadaAlta (7)0.07%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+404/11/202417/6/2026
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
AnalizadaMedia (5.3)0.30%—Iowacomputergurus Aspnetcore.utilities.cloudstorage30/10/202417/6/2026
ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not…
AnalizadaMedia (5.9)1.0%💥 PoCNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+827/10/202417/6/2026
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
AnalizadaAlta (7.8)0.12%—Qualcomm Snapdragon 8CX GEN 2 5G Compute Platform (sc8180x-ac) FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform (sc8180x-af) FirmwareQualcomm Snapdragon 8CX Compute Platform (sc8180xp-ac) FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform (sc8180xp-aa) Firmware+417/10/202417/6/2026
Memory corruption while taking snapshot when an offset variable is set by camera driver.
AnalizadaAlta (7.8)0.12%—Qualcomm Snapdragon 888+ 5G Mobile Platform (sm8350-ac) FirmwareQualcomm Snapdragon 865+ 5G Mobile Platform (sm8250-ab) FirmwareQualcomm Wsa8845h FirmwareQualcomm Wsa8845 Firmware+1147/10/202417/6/2026
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
AnalizadaMedia (5.4)0.26%—Cvat Computer Vision Annotation Tool30/9/202417/6/2026
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in this way is the same as the information…