Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
841 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.31% | — | Cvat Computer Vision Annotation Tool | 30/9/2024 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the… | |
| Analizada | Media (6.2) | 0.30% | — | Cvat Computer Vision Annotation Tool | 30/9/2024 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate any API calls on that… | |
| Analizada | Alta (7.7) | 1.3% | — | Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware | 12/9/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges. | |
| Analizada | Media (6.4) | 0.24% | — | Cvat Computer Vision Annotation Tool | 10/9/2024 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains information about the… | |
| Analizada | Alta (7.5) | 0.69% | — | Dfinity Canister Developer KIT FOR THE Internet Computer | 5/9/2024 | 17/6/2026 | When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple… | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+164 | 2/9/2024 | 17/6/2026 | Memory corruption while processing IOCTL call for getting group info. | |
| Analizada | Alta (7.8) | 0.17% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+246 | 2/9/2024 | 17/6/2026 | Memory corruption when two threads try to map and unmap a single node simultaneously. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Memory corruption when user provides data for FM HCI command control operations. | |
| Analizada | Alta (7.5) | 0.30% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9206 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 Firmware+285 | 2/9/2024 | 17/6/2026 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+176 | 2/9/2024 | 17/6/2026 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | |
| Analizada | Media (6.8) | 0.15% | — | Qualcomm Qcn9000 FirmwareQualcomm Qcn9011 FirmwareQualcomm Qcn9012 FirmwareQualcomm Qcn9013 Firmware+329 | 2/9/2024 | 17/6/2026 | memory corruption when an invalid firehose patch command is invoked. | |
| Analizada | Alta (7.5) | 0.30% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+175 | 2/9/2024 | 17/6/2026 | Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). | |
| Analizada | Alta (7.1) | 0.12% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+228 | 2/9/2024 | 17/6/2026 | Cryptographic issue while parsing RSA keys in COBR format. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Qcn9024 FirmwareQualcomm Qcs4490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 Firmware+157 | 2/9/2024 | 17/6/2026 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.1) | 0.46% | — | Oretnom23 Online Computer AND Laptop Store | 22/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /php-ocls/classes/SystemSettings.php?f=update_settings of the component Setting Handler. The manipulation of the argument System Name leads to cross site… | |
| Analizada | Media (5.3) | 0.57% | — | Oretnom23 Online Computer AND Laptop Store | 22/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /php-ocls/classes/Master.php?f=pay_order. The manipulation of the argument id leads to sql injection. The attack may be launched… | |
| Aplazada | Crítica (9.6) | 0.54% | — | Hamed Naderfar Compute LinksAIPHPAI | 19/8/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1. | |
| Aplazada | Media (6.8) | 0.29% | — | Ericsson RAN Compute AND Site Controller 6610AI | 16/8/2024 | 17/6/2026 | Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user… | |
| Analizada | Media (6.5) | 0.60% | — | Oretnom23 Computer Laboratory Management System | 12/8/2024 | 17/6/2026 | Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories. | |
| Modificada | Crítica (9.8) | 0.60% | — | Oretnom23 Computer Laboratory Management System | 7/8/2024 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. | |
| Analizada | Crítica (9.8) | 0.70% | — | Oretnom23 Computer Laboratory Management System | 7/8/2024 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. |