Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+235 | 3/3/2025 | 17/6/2026 | Memory corruption while calling the NPU driver APIs concurrently. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Sm6370 FirmwareQualcomm Sm6650 FirmwareQualcomm Sm7250p FirmwareQualcomm Sm7315 Firmware+247 | 3/3/2025 | 17/6/2026 | Memory corruption may occur while validating ports and channels in Audio driver. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+188 | 3/3/2025 | 17/6/2026 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm C-v2x 9150 Firmware+240 | 3/3/2025 | 17/6/2026 | Information disclosure while deriving keys for a session for any Widevine use case. | |
| Analizada | Media (5.3) | 0.27% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+160 | 3/3/2025 | 17/6/2026 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | |
| Aplazada | Alta (7.1) | 0.15% | — | Blackbam Tinymce Advanced Qtranslate FIX Editor ProblemsAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-problems allows Stored XSS.This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+28 | 3/2/2025 | 17/6/2026 | Memory corruption while handling IOCTL call from user-space to set latency level. | |
| Analizada | Alta (7) | 0.07% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+33 | 3/2/2025 | 17/6/2026 | Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+156 | 3/2/2025 | 17/6/2026 | Memory corruption while configuring a Hypervisor based input virtual device. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to read board data. | |
| Aplazada | Media (6.5) | 0.35% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter. | |
| Aplazada | Alta (7.5) | 0.46% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the… | |
| Aplazada | Media (4.3) | 0.29% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users. | |
| Analizada | Alta (7.5) | 0.59% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 19/12/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QTS… | |
| Aplazada | Media (4.3) | 0.40% | — | Onthegosystems Qtranslate X CleanupAIOnthegosystems Wpml ImportAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in OntheGoSystems qTranslate X Cleanup and WPML Import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects qTranslate X Cleanup and WPML Import: from n/a through 3.0.1. | |
| Analizada | Alta (8.7) | 23% | 💥 PoC | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (2.1) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.53% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Alta (8.7) | 1.3% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950… | |
| Analizada | Alta (8.7) | 0.44% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Media (5.3) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Baja (2.3) | 0.42% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Alta (7.3) | 0.15% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.3) | 0.58% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later… |