Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.17%—Trustedfirmware Op-tee3/6/202622/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability exists in OP-TEE OS when processing an FFA_MEM_SHARE request from the…
AnalizadaMedia (4.7)0.09%—Trustedfirmware Op-tee3/6/202622/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't verified to be a point on the correct curve. By passing approximately…
AnalizadaAlta (7.8)0.21%—Trustedfirmware Op-tee3/6/202621/7/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A within OP-TEE…
AnalizadaAlta (8.7)0.58%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
AnalizadaAlta (8.7)0.58%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
AnalizadaAlta (8.7)0.58%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
AnalizadaAlta (8.7)0.68%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
AnalizadaAlta (7.2)0.53%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
AnalizadaCrítica (9.3)0.59%—Mbs-solutions Universal Gateway Firmware3/6/202622/7/2026
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
AnalizadaAlta (7.1)0.30%—Tp-link Tapo C200 Firmware2/6/202622/7/2026
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an…
ModificadaMedia (6.5)0.99%—Vivotek Fd8136 Firmware2/6/202622/7/2026
A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.
ModificadaMedia (6.3)0.44%—Vivotek Fd8136 Firmware2/6/202622/7/2026
A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or…
ModificadaAlta (8.8)0.76%—Vivotek Fd8136 Firmware2/6/202622/7/2026
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.
ModificadaAlta (8.8)0.89%—Vivotek Fd8136 Firmware2/6/202622/7/2026
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.
ModificadaAlta (7.3)0.49%—Vivotek Fd8136 Firmware2/6/202622/7/2026
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component
ModificadaMedia (6.3)0.44%—Vivotek Fd8136 Firmware2/6/202622/7/2026
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length…
AnalizadaMedia (5.3)0.20%—Draeger Infinity Delta FirmwareDraeger Delta XL FirmwareDraeger Kappa Firmware2/6/202622/7/2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the…
AnalizadaAlta (8.8)0.07%—Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+531/6/202622/7/2026
Memory corruption while using Strongbox due to buffer overflow.
AnalizadaAlta (8.8)0.07%—Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+531/6/202622/7/2026
Memory corruption while using Strongbox due to missing bounds check.
AnalizadaAlta (7)0.05%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+311/6/202622/7/2026
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.