Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.41% | — | Cloudnet360 | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8052 Firmware+255 | 7/11/2023 | 17/6/2026 | Memory corruption in Audio while processing the VOC packet data from ADSP. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+161 | 7/11/2023 | 17/6/2026 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | |
| Modificada | Media (5.5) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+204 | 7/11/2023 | 17/6/2026 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | |
| Modificada | Media (5.5) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+121 | 7/11/2023 | 17/6/2026 | Information disclosure in WLAN HAL while handling the WMI state info command. | |
| Modificada | Media (5.5) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+226 | 7/11/2023 | 17/6/2026 | Information disclosure in IOE Firmware while handling WMI command. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+222 | 7/11/2023 | 17/6/2026 | Cryptographic issue in HLOS during key management. | |
| Modificada | Alta (7.8) | 0.14% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+200 | 7/11/2023 | 17/6/2026 | Memory corruption in TZ Secure OS while loading an app ELF. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 7/11/2023 | 17/6/2026 | Memory Corruption in Core due to secure memory access by user while loading modem image. | |
| Modificada | Crítica (9.8) | 0.35% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+225 | 7/11/2023 | 17/6/2026 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | |
| Modificada | Media (5.4) | 0.31% | — | Chrisyee Momentopress FOR Momento360 | 6/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Yee MomentoPress for Momento360 plugin <= 1.0.1 versions. | |
| Modificada | Media (6.5) | 0.62% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 19/10/2023 | 17/6/2026 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (5.3) | 0.65% | — | Maurice Vrm360 | 16/10/2023 | 17/6/2026 | The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existent file in a parameter of the shortcode. | |
| Modificada | Media (5.5) | 0.16% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user. | |
| Modificada | Media (5.5) | 0.17% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe. | |
| Modificada | Media (6.7) | 0.18% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM. | |
| Modificada | Alta (7.8) | 0.16% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe. | |
| Modificada | Alta (7.8) | 0.17% | — | Samsung Galaxy Book FirmwareSamsung Galaxy Book PRO FirmwareSamsung Galaxy Book PRO 360 FirmwareSamsung Galaxy Book Odyssey Firmware | 4/10/2023 | 17/6/2026 | An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption. | |
| Modificada | Alta (7.5) | 0.39% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+324 | 3/10/2023 | 17/6/2026 | Transient DOS in WLAN Firmware while parsing rsn ies. | |
| Modificada | Alta (7.5) | 0.43% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+148 | 3/10/2023 | 17/6/2026 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | |
| Modificada | Alta (7.5) | 0.36% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8017 Firmware+234 | 3/10/2023 | 17/6/2026 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | |
| Modificada | Alta (7.5) | 0.36% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8017 Firmware+240 | 3/10/2023 | 17/6/2026 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | |
| Modificada | Alta (7.5) | 0.39% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+253 | 3/10/2023 | 17/6/2026 | Transient DOS in Modem while allocating DSM items. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+62 | 3/10/2023 | 17/6/2026 | Transient DOS in Modem while triggering a camping on an 5G cell. |