Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
891 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.19% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this… | |
| Analizada | Media (6.7) | 0.21% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A… | |
| Analizada | Media (6.1) | 0.53% | — | Cisco Prime Collaboration Deployment | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate… | |
| Analizada | Media (4.4) | 0.19% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco Telepresence Collaboration Endpoint | 15/11/2024 | 17/6/2026 | A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability is due to insufficient version control. An attacker could exploit this… | |
| Analizada | Media (6.8) | 0.43% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to insufficient identity verification. An attacker… | |
| Analizada | Media (6.1) | 61% | — | Synacor Zimbra Collaboration Suite | 7/11/2024 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Snapdragon W5+ GEN 1 Wearable Platform FirmwareQualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 8+ GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform (sm4350-ac) Firmware+115 | 4/11/2024 | 17/6/2026 | Memory corruption during GNSS HAL process initialization. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 FirmwareQualcomm Wsa8810 Firmware+202 | 4/11/2024 | 17/6/2026 | Memory corruption while processing GPU page table switch. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+264 | 4/11/2024 | 17/6/2026 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+73 | 4/11/2024 | 17/6/2026 | Memory corruption while processing GPU commands. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+144 | 4/11/2024 | 17/6/2026 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+174 | 4/11/2024 | 17/6/2026 | Memory corruption while handling session errors from firmware. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+21 | 4/11/2024 | 17/6/2026 | Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+21 | 4/11/2024 | 17/6/2026 | Memory corruption while station LL statistic handling. | |
| Analizada | Crítica (9.1) | 0.14% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+231 | 4/11/2024 | 17/6/2026 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | |
| Analizada | Alta (7) | 0.07% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+40 | 4/11/2024 | 17/6/2026 | Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver. | |
| Analizada | Alta (7) | 0.07% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+40 | 4/11/2024 | 17/6/2026 | Memory corruption while handling IOCTL calls in JPEG Encoder driver. | |
| Analizada | Media (6.5) | 0.25% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+95 | 4/11/2024 | 17/6/2026 | Transient DOS while processing the CU information from RNR IE. | |
| Analizada | Media (6.5) | 0.25% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+118 | 4/11/2024 | 17/6/2026 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. | |
| Analizada | Media (6.7) | 0.10% | — | Qualcomm Wsa8835 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 Firmware+65 | 4/11/2024 | 17/6/2026 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. | |
| Analizada | Media (6.7) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+35 | 4/11/2024 | 17/6/2026 | Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver. | |
| Aplazada | Media (5.3) | 0.38% | — | Atarim-visual-collaborationAIAtarimAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration.This issue affects Atarim: from n/a through <= 4.0.1. | |
| Analizada | Alta (8.8) | 21% | — | Zimbra Collaboration | 22/10/2024 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits… | |
| Analizada | Alta (7.8) | 0.67% | ⚠ Explotación activa | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+60 | 7/10/2024 | 17/6/2026 | Memory corruption while maintaining memory maps of HLOS memory. |