Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Mdm8207 Firmware+9 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. | |
| Modificada | Crítica (9.8) | 0.42% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | memory corruption in modem due to improper check while calculating size of serialized CoAP message | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message | |
| Modificada | Crítica (9.8) | 0.42% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Mdm8207 Firmware+22 | 13/4/2023 | 17/6/2026 | Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Information disclosure in modem due to missing NULL check while reading packets received from local network | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Mdm8207 Firmware+9 | 13/4/2023 | 17/6/2026 | Information disclosure in modem due to buffer over-read while processing packets from DNS server | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+23 | 13/4/2023 | 17/6/2026 | Information disclosure in modem due to improper check of IP type while processing DNS server query | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Wcn685x-1 Firmware+22 | 13/4/2023 | 17/6/2026 | Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet | |
| Modificada | Crítica (9.8) | 0.42% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+8 | 13/4/2023 | 17/6/2026 | Memory correction in modem due to buffer overwrite during coap connection | |
| Modificada | Alta (8.3) | 1.3% | — | Intel 2G Modem Firmware | 5/4/2018 | 17/6/2026 | Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network. | |
| Modificada | Alta (7.5) | 1.3% | — | Vivo Modem Firmware | 8/12/2017 | 17/6/2026 | Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | EIR D1000 Modem Firmware | 16/5/2017 | 17/6/2026 | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature. | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Crítica (9.8) | 6.9% | — | Cisco Dpc2203 Cable Modem FirmwareCisco Epc2203 Cable Modem Firmware | 9/3/2016 | 17/6/2026 | Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Huawei WebuiHuawei E303 Modem FirmwareHuawei E303 Modem | 2/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML… | |
| Modificada | Media (4.7) | 0.47% | 💥 Exploit | Huawei Mt882 Modem FirmwareHuawei Mt882 Modem | 4/12/2009 | 16/6/2026 | rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete. |