Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

891 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.26%—Qualcomm Qcn9024 FirmwareQualcomm Qcs4490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 Firmware+1572/9/202417/6/2026
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
ModificadaMedia (5.4)0.26%—Zimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious…
ModificadaAlta (7.5)0.55%—Zimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication,…
ModificadaMedia (5.4)0.28%—Zimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to…
AnalizadaMedia (6.1)24%⚠ Explotación activa💥 ExploitZimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email…
AnalizadaAlta (7.8)0.35%—Zimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privileges from the zimbra user to root, because of improper handling…
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1015/8/202417/6/2026
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
AnalizadaAlta (7.8)0.11%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1345/8/202417/6/2026
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm C-v2x 9150 Firmware+865/8/202417/6/2026
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1615/8/202417/6/2026
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
AnalizadaAlta (7.5)0.28%—Qualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1655/8/202417/6/2026
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1775/8/202417/6/2026
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
AnalizadaAlta (7.8)0.11%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1535/8/202417/6/2026
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
AnalizadaAlta (7.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1205/8/202417/6/2026
Memory corruption while allocating memory in HGSL driver.
AnalizadaAlta (7.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1345/8/202417/6/2026
Memory corruption while processing IOCTL call to set metainfo.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+945/8/202417/6/2026
Transient DOS while processing TID-to-link mapping IE elements.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1455/8/202417/6/2026
Transient DOS while parsing the received TID-to-link mapping action frame.
AnalizadaAlta (7.5)0.33%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1475/8/202417/6/2026
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1915/8/202417/6/2026
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
AnalizadaAlta (7.5)0.32%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+3215/8/202417/6/2026
Transient DOS while parsing ESP IE from beacon/probe response frame.
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1665/8/202417/6/2026
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2455/8/202417/6/2026
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2455/8/202417/6/2026
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2445/8/202417/6/2026
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
AnalizadaAlta (8.4)0.11%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1005/8/202417/6/2026
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.