Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1665/8/202417/6/2026
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2455/8/202417/6/2026
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
AnalizadaAlta (7.5)0.28%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2455/8/202417/6/2026
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
AnalizadaAlta (7.5)0.28%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2445/8/202417/6/2026
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
AnalizadaMedia (5.5)0.09%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2385/8/202417/6/2026
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
AnalizadaAlta (7.5)0.26%—Qualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 FirmwareQualcomm Wsa8810 Firmware+1255/8/202417/6/2026
Information disclosure while handling beacon probe frame during scan entry generation in client side.
AnalizadaAlta (7.5)0.26%—Qualcomm Snapdragon W5+ GEN 1 Wearable Platform FirmwareQualcomm Snapdragon 870 5G Mobile Platform (sm8250-ac) FirmwareQualcomm Snapdragon 865+ 5G Mobile Platform (sm8250-ab) FirmwareQualcomm Wsa8835 Firmware+1715/8/202417/6/2026
Information disclosure while handling beacon or probe response frame in STA.
AplazadaAlta (8.3)0.65%—Homebrew BrewAI31/7/202417/6/2026
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occurs before a user…
ModificadaMedia (5.3)0.53%—Home Owners Collection Management System Project Home Owners Collection Management System2/7/202417/6/2026
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaMedia (5.3)0.68%—Home Owners Collection Management System Project Home Owners Collection Management System2/7/202417/6/2026
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has…
ModificadaAlta (7.8)0.10%—Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+3391/7/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition.
ModificadaAlta (7.8)0.11%—Qualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform Firmware+651/7/202417/6/2026
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.
ModificadaAlta (7.5)0.21%—Qualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform FirmwareQualcomm Ipq5300 Firmware+601/7/202417/6/2026
Information disclosure while parsing sub-IE length during new IE generation.
ModificadaMedia (5.5)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+3071/7/202417/6/2026
Transient DOS while loading the TA ELF file.
ModificadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+3091/7/202417/6/2026
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
ModificadaAlta (7.5)0.21%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 Platform Firmware+1071/7/202417/6/2026
Information disclosure while handling SA query action frame.
ModificadaAlta (7.5)0.21%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 Platform Firmware+1071/7/202417/6/2026
INformation disclosure while handling Multi-link IE in beacon frame.
AplazadaMedia (6.9)0.43%—Genexis Tilgin Fiber Home Gateway Hg1522AI26/6/202417/6/2026
A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be…
AplazadaMedia (5.9)0.32%—Sandisk IBIAIWesterndigital MY CloudAIWesterndigital MY Cloud HomeAIWesterndigital WD CloudAI24/6/202417/6/2026
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious…
AplazadaMedia (6.9)0.43%—Genexis Tilgin Home GatewayAI18/6/202417/6/2026
A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# of the component Login. The manipulation of the argument errmsg leads to basic cross site scripting. It is…
AplazadaAlta (8.8)0.21%—AdguardhomeAI13/6/202417/6/2026
An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.
ModificadaMedia (6.5)0.37%—Schneider-electric Evlink Home Firmware12/6/202417/6/2026
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts are limited to port…
ModificadaCrítica (9.8)0.99%—Homebrew JAN4/6/202417/6/2026
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaCrítica (9.8)3.0%💥 ExploitHomebrew JAN4/6/202417/6/2026
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaAlta (7.5)2.1%💥 ExploitHomebrew JAN4/6/202417/6/2026
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
Orbitaley — Vulnerabilidades