Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

891 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm8550 FirmwareQualcomm Qcs6490 Firmware+143/2/202517/6/2026
Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.
AnalizadaAlta (7.5)0.36%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1796/1/202517/6/2026
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
AnalizadaAlta (7.8)0.13%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1246/1/202517/6/2026
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
AnalizadaAlta (7.8)0.13%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+476/1/202517/6/2026
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+476/1/202517/6/2026
Memory corruption when IOCTL call is invoked from user-space to read board data.
AnalizadaMedia (5.5)0.10%—Qualcomm Ar8035 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6800 Firmware+736/1/202517/6/2026
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+356/1/202517/6/2026
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
AnalizadaAlta (7.8)0.13%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+316/1/202517/6/2026
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
AnalizadaAlta (7.5)0.59%—Synacor Zimbra Collaboration Suite19/12/202417/6/2026
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth…
AnalizadaAlta (7.8)0.10%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+872/12/202417/6/2026
Memory corruption while processing API calls to NPU with invalid input.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+502/12/202417/6/2026
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
AnalizadaAlta (7.5)0.26%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform Firmware+1202/12/202417/6/2026
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+3252/12/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
AnalizadaMedia (6.7)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+522/12/202417/6/2026
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csrb31024 Firmware+2072/12/202417/6/2026
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
AnalizadaMedia (6.1)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Qam8295p Firmware+472/12/202417/6/2026
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
AnalizadaMedia (6.7)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+482/12/202417/6/2026
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
AnalizadaMedia (5.4)0.52%—Synacor Zimbra Collaboration Suite21/11/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's session. This issue is caused by improper sanitization of user input,…
AnalizadaMedia (4.8)0.38%—Synacor Zimbra Collaboration Suite21/11/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript code in the context of the victim's browser when a crafted vCard…
AnalizadaMedia (4.8)0.46%—Synacor Zimbra Collaboration Suite21/11/202417/6/2026
In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaScript code while configuring an email account. This injected code is…
AnalizadaMedia (5.4)0.63%—Synacor Zimbra Collaboration Suite21/11/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and…
AnalizadaMedia (5.4)0.38%—Synacor Zimbra Collaboration Suite21/11/202417/6/2026
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in…
AnalizadaMedia (5.4)0.31%—Synacor Zimbra Collaboration Suite20/11/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the victim adds the…
AnalizadaMedia (5.4)0.31%—Synacor Zimbra Collaboration Suite20/11/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a…
AnalizadaMedia (4.3)0.27%—Cisco Telepresence Collaboration EndpointCisco Roomos15/11/202417/6/2026
A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request…