Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.21%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+19924/9/202517/6/2026
Transient DOS while parsing the EPTM test control message to get the test pattern.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc5161 Firmware+4924/9/202517/6/2026
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p Firmware+3324/9/202517/6/2026
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
AnalizadaCrítica (9.8)0.40%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6174a FirmwareQualcomm Qca6391 Firmware+10924/9/202517/6/2026
Memory corruption while selecting the PLMN from SOR failed list.
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+18824/9/202517/6/2026
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
AnalizadaCrítica (9.8)0.40%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+22324/9/202517/6/2026
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
AnalizadaAlta (7.8)0.07%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+24524/9/202517/6/2026
Memory corruption while performing private key encryption in trusted application.
AnalizadaAlta (8.2)0.27%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+10424/9/202525/9/2026
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
AnalizadaAlta (8.2)0.26%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+22324/9/202525/9/2026
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
AnalizadaAlta (8.2)0.26%—Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+16924/9/202525/9/2026
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
AnalizadaAlta (7.1)0.08%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+28324/9/202525/9/2026
Cryptographic issue while performing RSA PKCS padding decoding.
AplazadaMedia (6.5)0.28%—Anadolu Hayat Emeklilik AHE MobileAI23/9/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse. This issue affects AHE Mobile: from 1.9.7 before 1.9.9.
AplazadaAlta (7.1)0.68%💥 PoCT-mobile G2AI22/9/202517/6/2026
GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior. The vendor did not respond in any way. Only version…
AplazadaMedia (6.5)0.30%—Axis Bank Limited Axis Mobile APPAI12/9/20255/7/2026
An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not…
AplazadaMedia (4.3)0.24%—Yydevelopment Mobile Contact LineAI3/9/202517/6/2026
Missing Authorization vulnerability in yydevelopment Mobile Contact Line mobile-contact-line allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile Contact Line: from n/a through <= 2.4.0.
AnalizadaBaja (2.1)0.33%—Fabian Mobile Shop Management System3/9/202517/6/2026
A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed…
AnalizadaMedia (6.5)0.60%—Opensecurity Mobile Security Framework2/9/202517/6/2026
MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1.
AnalizadaBaja (1.3)0.78%—Opensecurity Mobile Security Framework2/9/202517/6/2026
MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the…
AplazadaBaja (2)0.26%—Weaver E-mobile Mobile Management PlatformAI28/8/202525/9/2026
A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerability is an unknown functionality. The manipulation of the argument gohome leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The…
AplazadaMedia (6.5)0.21%—Itayxd Responsive-mobile-friendly-tooltipAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ItayXD Responsive Mobile-Friendly Tooltip responsive-mobile-friendly-tooltip allows Stored XSS.This issue affects Responsive Mobile-Friendly Tooltip: from n/a through <= 1.6.6.
AplazadaAlta (8.8)0.36%—Touch Lebanon Mobile APPAI20/8/202517/6/2026
A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate…
AplazadaMedia (5.3)0.29%—Mobile-industrial-robots MIR SoftwareAI20/8/202517/6/2026
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.
AplazadaCrítica (10)1.9%💥 ExploitMobilecartlyAI8/8/202516/6/2026
MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization checks before invoking file_put_contents() on attacker-controlled input. An unauthenticated attacker can exploit this flaw by sending crafted HTTP GET…
AplazadaMedia (6.5)0.40%—Mobile-industrial-robots MIR SoftwareAI8/8/202517/6/2026
Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated users to extract files from the robot file system via a crafted API request.
AnalizadaMedia (5.4)0.46%—Checkpoint Mobile AccessCheckpoint Remote Access VPN6/8/202517/6/2026
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.