Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.66%—SEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI4/6/202417/6/2026
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
AplazadaAlta (8.3)5.5%💥 ExploitSEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI4/6/202417/6/2026
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+93/6/202417/6/2026
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
AnalizadaAlta (8.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+643/6/202417/6/2026
Memory corruption in Hypervisor when platform information mentioned is not aligned.
AnalizadaAlta (7.5)0.24%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1153/6/202417/6/2026
Information disclosure in Video while parsing mp2 clip with invalid section length.
AnalizadaAlta (7.5)0.26%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+2373/6/202417/6/2026
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
AnalizadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2053/6/202417/6/2026
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+1333/6/202417/6/2026
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
ModificadaMedia (5.5)0.50%—Linux KernelNetapp Converged Systems Advisor AgentNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+630/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4().
AnalizadaMedia (6.1)0.47%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.
AnalizadaMedia (6.1)0.42%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.
AnalizadaMedia (6.1)0.43%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
AplazadaAlta (8.8)0.47%—Asustek Computer INC Asus GPU TweakiiAI22/5/202417/6/2026
An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
AplazadaAlta (8.4)0.19%—Asustek Computer INC Asus Atszio DriverAI22/5/202417/6/2026
An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
AplazadaAlta (7.8)0.18%—Asustek Computer Asus Bios Flash DriverAI22/5/202417/6/2026
An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
AnalizadaMedia (6.7)0.37%—Intel TDX ModuleNetapp HCI Compute Node Bios16/5/202431/8/2026
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaAlta (8.2)0.38%—Intel TDX ModuleNetapp HCI Compute Node Bios16/5/202431/8/2026
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.3)1.1%—Oretnom23 Online Computer AND Laptop Store14/5/202417/6/2026
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be launched remotely.…
AnalizadaMedia (5.3)0.95%—Oretnom23 Online Computer AND Laptop Store14/5/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched…
AnalizadaMedia (6.1)0.57%💥 PoCOretnom23 Computer Laboratory Management System14/5/202417/6/2026
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
AnalizadaAlta (7.3)0.87%💥 PoCOretnom23 Computer Laboratory Management System14/5/202417/6/2026
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
AnalizadaAlta (7.3)0.32%—Carmelo Computer Book Store14/5/202417/6/2026
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
AnalizadaAlta (7.5)0.32%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+1806/5/202417/6/2026
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2326/5/202417/6/2026
Memory corruption when the payload received from firmware is not as per the expected protocol size.
AnalizadaAlta (7.8)0.11%—Qualcomm Ar8035 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1716/5/202417/6/2026
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.