Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.48% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… | |
| Analizada | Media (6.3) | 0.27% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit… | |
| Analizada | Alta (7.5) | 0.28% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a… | |
| Analizada | Alta (7.5) | 0.17% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain the ability to pair a malicious… | |
| Analizada | Media (6.5) | 0.55% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is required to exploit this… | |
| Analizada | Alta (8.8) | 0.41% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged… | |
| Aplazada | Media (4.6) | 0.29% | — | Hexagon Hxgn Oncall Dispatch Advantage WEBAIHexagon Hxgn Oncall Dispatch Advantage MobileAI | 25/6/2025 | 17/6/2026 | Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code. | |
| Aplazada | Crítica (10) | 0.32% | — | Ataturk University Ata-aof Mobile ApplicationAI | 24/6/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025. | |
| Modificada | Media (4.8) | 0.27% | — | M-files Mobile | 16/6/2025 | 17/6/2026 | An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs. | |
| Aplazada | Media (6.5) | 0.25% | — | Sevenspark Shiftnav Responsive Mobile MenuAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark ShiftNav – Responsive Mobile Menu shiftnav-responsive-mobile-menu allows Stored XSS.This issue affects ShiftNav – Responsive Mobile Menu: from n/a through <= 1.8. | |
| Analizada | Alta (8.6) | 0.84% | ⚠ Explotación activa💥 PoC | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+71 | 3/6/2025 | 17/6/2026 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | |
| Analizada | Alta (7.5) | 1.0% | ⚠ Explotación activa | Qualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 7800 Firmware+40 | 3/6/2025 | 17/6/2026 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | |
| Analizada | Alta (7.5) | 0.24% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform FirmwareQualcomm Ipq5300 Firmware+63 | 3/6/2025 | 17/6/2026 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qmp1000 FirmwareQualcomm Sm8735 Firmware+25 | 3/6/2025 | 17/6/2026 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. | |
| Analizada | Alta (8.6) | 0.46% | ⚠ Explotación activa | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+72 | 3/6/2025 | 17/6/2026 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | |
| Analizada | Alta (7.5) | 0.23% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+207 | 3/6/2025 | 17/6/2026 | Transient DOS while processing the EHT operation IE in the received beacon frame. | |
| Analizada | Alta (8.2) | 0.30% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+221 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while processing goodbye RTCP packet from network. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+77 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. | |
| Analizada | Media (6.6) | 0.08% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sdm429w FirmwareQualcomm Snapdragon 429 Mobile Platform Firmware+15 | 3/6/2025 | 17/6/2026 | Memory corruption may occur while processing the OIS packet parser. |