Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8052 Firmware+255 | 7/11/2023 | 17/6/2026 | Memory corruption in Audio while processing the VOC packet data from ADSP. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+161 | 7/11/2023 | 17/6/2026 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | |
| Modificada | Media (5.5) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csr8811 Firmware+144 | 7/11/2023 | 17/6/2026 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | |
| Modificada | Crítica (9.8) | 0.35% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+225 | 7/11/2023 | 17/6/2026 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | |
| Modificada | Media (6.5) | 0.54% | — | IBM Robotic Process Automation FOR Cloud PAK | 3/11/2023 | 17/6/2026 | A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.67% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 6/10/2023 | 17/6/2026 | IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527. | |
| Modificada | Alta (7.5) | 0.43% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+148 | 3/10/2023 | 17/6/2026 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | |
| Modificada | Alta (7.5) | 0.36% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8017 Firmware+234 | 3/10/2023 | 17/6/2026 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | |
| Modificada | Alta (7.5) | 0.36% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8017 Firmware+240 | 3/10/2023 | 17/6/2026 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | |
| Modificada | Crítica (9.8) | 0.42% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+237 | 3/10/2023 | 17/6/2026 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | |
| Modificada | Media (5.3) | 0.49% | — | IBM Robotic Process Automation | 20/9/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606. | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation | 11/9/2023 | 17/6/2026 | A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8076 FirmwareQualcomm Apq8084 FirmwareQualcomm Apq8092 FirmwareQualcomm Apq8094 Firmware+263 | 5/9/2023 | 17/6/2026 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | |
| Modificada | Media (5.3) | 0.48% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470. | |
| Modificada | Crítica (9.8) | 0.70% | — | IBM Robotic Process Automation | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. | |
| Modificada | Media (4.3) | 0.49% | — | IBM Robotic Process Automation | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. | |
| Modificada | Media (4.3) | 0.53% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver Process Integration | 8/8/2023 | 17/6/2026 | In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on confidentiality and integrity of the system. | |
| Modificada | Media (6.5) | 0.49% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 2/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425. | |
| Modificada | Media (5.3) | 0.51% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 19/7/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 259368. |