Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
841 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+153 | 5/8/2024 | 17/6/2026 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+321 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing ESP IE from beacon/probe response frame. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+245 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+245 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+244 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+238 | 5/8/2024 | 17/6/2026 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+206 | 5/8/2024 | 17/6/2026 | Memory corruption during session sign renewal request calls in HLOS. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+138 | 5/8/2024 | 17/6/2026 | Memory corruption when keymaster operation imports a shared key. | |
| Analizada | Alta (7.5) | 0.35% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+245 | 5/8/2024 | 17/6/2026 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | |
| Analizada | Alta (7.5) | 0.35% | — | Qualcomm Snapdragon 855+/860 Mobile Platform (sm8150-ac) FirmwareQualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 Firmware+101 | 5/8/2024 | 17/6/2026 | Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. | |
| Analizada | Alta (8.4) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+162 | 5/8/2024 | 17/6/2026 | Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | |
| Analizada | Media (4.2) | 0.33% | — | Netapp HCI Compute NodeNeovimVIM | 1/8/2024 | 17/9/2026 | Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However,… | |
| Modificada | Media (5.3) | 9.1% | — | Computer Laboratory Management System Project Computer Laboratory Management System | 17/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Alta (7.8) | 0.15% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+218 | 1/7/2024 | 17/6/2026 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | |
| Modificada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+107 | 1/7/2024 | 17/6/2026 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+339 | 1/7/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+220 | 1/7/2024 | 17/6/2026 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+255 | 1/7/2024 | 17/6/2026 | Memory corruption while processing key blob passed by the user. | |
| Modificada | Media (5.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+307 | 1/7/2024 | 17/6/2026 | Transient DOS while loading the TA ELF file. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+309 | 1/7/2024 | 17/6/2026 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. | |
| Aplazada | Media (5.3) | 0.27% | — | Fastly Js-computeAI | 26/6/2024 | 17/6/2026 | @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a… | |
| Aplazada | Media (5.4) | 0.42% | — | Envisionware Computer Access AND Reservation Control SelfcheckAIEnvisionware OnestopAI | 24/6/2024 | 17/6/2026 | An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal. | |
| Analizada | Media (6.1) | 0.48% | — | Oretnom23 Computer Laboratory Management System | 20/6/2024 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters. | |
| Analizada | Alta (7.1) | 0.21% | — | Cvat Computer Vision Annotation Tool | 13/6/2024 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export or a backup from a project, task or job… | |
| Analizada | Alta (8.5) | 0.35% | — | Cvat Computer Vision Annotation Tool | 13/6/2024 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob Storage. Starting in version 2.1.0 and prior to version 2.14.3, an attacker with a CVAT account can exploit… |