Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.17% | — | Trustedfirmware Op-tee | 3/6/2026 | 22/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability exists in OP-TEE OS when processing an FFA_MEM_SHARE request from the… | |
| Analizada | Media (4.7) | 0.09% | — | Trustedfirmware Op-tee | 3/6/2026 | 22/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't verified to be a point on the correct curve. By passing approximately… | |
| Analizada | Alta (7.8) | 0.21% | — | Trustedfirmware Op-tee | 3/6/2026 | 21/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A within OP-TEE… | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.68% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Crítica (9.3) | 0.59% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. | |
| Analizada | Alta (7.1) | 0.30% | — | Tp-link Tapo C200 Firmware | 2/6/2026 | 22/7/2026 | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an… | |
| Modificada | Media (6.5) | 0.99% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request. | |
| Modificada | Media (6.3) | 0.44% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or… | |
| Modificada | Alta (8.8) | 0.76% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device. | |
| Modificada | Alta (8.8) | 0.89% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely. | |
| Modificada | Alta (7.3) | 0.49% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component | |
| Modificada | Media (6.3) | 0.44% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length… | |
| Analizada | Media (5.3) | 0.20% | — | Draeger Infinity Delta FirmwareDraeger Delta XL FirmwareDraeger Kappa Firmware | 2/6/2026 | 22/7/2026 | Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the… | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to buffer overflow. | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to missing bounds check. | |
| Analizada | Alta (7) | 0.05% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+31 | 1/6/2026 | 22/7/2026 | Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. |