Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)2.7%—Geovision Gv-i/o BOX 4EAI24/6/202625/6/2026
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various…
AplazadaCrítica (10)0.60%💥 PoCGeovision Gv-i O BOX 4EAI24/6/202625/6/2026
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a…
AplazadaAlta (7.5)0.48%—Cozyvision SMS Alert Order NotificationsAI17/6/202617/6/2026
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
AplazadaAlta (7.2)0.42%—Foliovision FV Flowplayer Video PlayerAI9/6/202623/7/2026
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
Pendiente de análisisMedia (6.6)0.35%—SAP Operational Data Provisioning Data Replication APIAI9/6/202623/7/2026
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its intended usage. Which could lead to…
Pendiente de análisisAlta (8.3)0.12%—Drager Cc-vision BasicAIDrager Cc-vision E-calAI2/6/202622/7/2026
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.
AnalizadaAlta (7.2)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+2691/6/202622/7/2026
Memory corruption while processing fastboot commands with improperly formatted input.
AnalizadaAlta (8.2)0.07%💥 PoCQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2421/6/202622/7/2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
AnalizadaAlta (7.2)0.10%—Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+2691/6/202622/7/2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
AnalizadaMedia (6.4)0.06%—Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+2321/6/202622/7/2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
AplazadaAlta (7.5)0.39%—BEN Balter WP Document RevisionsAI1/6/202622/7/2026
Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.
AnalizadaAlta (8.7)0.39%—Suse Local Path Provisioner28/5/202617/6/2026
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The…
AnalizadaAlta (8.8)0.46%—Intel Vision12/5/202631/8/2026
Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable remote code execution. This result may potentially occur via network…
AnalizadaAlta (7.5)0.78%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination…
AnalizadaMedia (6.2)0.18%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a…
ModificadaAlta (7.5)0.42%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
AnalizadaMedia (4.7)0.11%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/5/202617/6/2026
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
ModificadaAlta (7.5)0.54%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/8/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
AnalizadaAlta (7.5)0.52%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.
AnalizadaMedia (4.3)0.43%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the…
ModificadaMedia (5.5)0.13%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/8/2026
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.
ModificadaAlta (8.8)0.15%💥 PoCApple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202621/8/2026
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.
AnalizadaMedia (5.5)0.15%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/5/202617/6/2026
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data.
AnalizadaMedia (4.7)0.11%💥 PoCApple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.
AnalizadaAlta (7.5)0.59%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
Orbitaley — Vulnerabilidades