Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.31%—Cvat Computer Vision Annotation Tool30/9/202417/6/2026
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the…
AnalizadaMedia (6.2)0.30%—Cvat Computer Vision Annotation Tool30/9/202417/6/2026
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate any API calls on that…
AnalizadaAlta (7.7)1.3%—Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware12/9/202417/6/2026
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
AnalizadaMedia (6.4)0.24%—Cvat Computer Vision Annotation Tool10/9/202417/6/2026
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains information about the…
AnalizadaAlta (7.5)0.69%—Dfinity Canister Developer KIT FOR THE Internet Computer5/9/202417/6/2026
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple…
AnalizadaAlta (7.8)0.16%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1642/9/202417/6/2026
Memory corruption while processing IOCTL call for getting group info.
AnalizadaAlta (7.8)0.17%—Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2462/9/202417/6/2026
Memory corruption when two threads try to map and unmap a single node simultaneously.
AnalizadaAlta (7.8)0.13%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1992/9/202417/6/2026
Memory corruption when user provides data for FM HCI command control operations.
AnalizadaAlta (7.5)0.30%—Qualcomm 315 5G IOT FirmwareQualcomm 9206 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 Firmware+2852/9/202417/6/2026
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
AnalizadaAlta (7.8)0.12%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1762/9/202417/6/2026
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
AnalizadaMedia (5.5)0.09%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1992/9/202417/6/2026
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
AnalizadaMedia (6.8)0.15%—Qualcomm Qcn9000 FirmwareQualcomm Qcn9011 FirmwareQualcomm Qcn9012 FirmwareQualcomm Qcn9013 Firmware+3292/9/202417/6/2026
memory corruption when an invalid firehose patch command is invoked.
AnalizadaAlta (7.5)0.30%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1752/9/202417/6/2026
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
AnalizadaAlta (7.1)0.12%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2282/9/202417/6/2026
Cryptographic issue while parsing RSA keys in COBR format.
AnalizadaAlta (8.2)0.26%—Qualcomm Qcn9024 FirmwareQualcomm Qcs4490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 Firmware+1572/9/202417/6/2026
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched…
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.…
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack…
AnalizadaMedia (5.1)0.46%—Oretnom23 Online Computer AND Laptop Store22/8/202417/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /php-ocls/classes/SystemSettings.php?f=update_settings of the component Setting Handler. The manipulation of the argument System Name leads to cross site…
AnalizadaMedia (5.3)0.57%—Oretnom23 Online Computer AND Laptop Store22/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /php-ocls/classes/Master.php?f=pay_order. The manipulation of the argument id leads to sql injection. The attack may be launched…
AplazadaCrítica (9.6)0.54%—Hamed Naderfar Compute LinksAIPHPAI19/8/202417/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.
AplazadaMedia (6.8)0.29%—Ericsson RAN Compute AND Site Controller 6610AI16/8/202417/6/2026
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user…
AnalizadaMedia (6.5)0.60%—Oretnom23 Computer Laboratory Management System12/8/202417/6/2026
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
ModificadaCrítica (9.8)0.60%—Oretnom23 Computer Laboratory Management System7/8/202417/6/2026
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
AnalizadaCrítica (9.8)0.70%—Oretnom23 Computer Laboratory Management System7/8/202417/6/2026
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
Orbitaley — Vulnerabilidades