Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+121 | 3/6/2024 | 17/6/2026 | Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+108 | 3/6/2024 | 17/6/2026 | Information disclosure while handling T2LM Action Frame in WLAN Host. | |
| Aplazada | Alta (7.1) | 0.30% | — | Nuki BridgeAINuki Home Solutions BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects… | |
| Aplazada | Media (6.3) | 1.3% | — | Nuki BridgeAINuki Home SolutionsAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+180 | 6/5/2024 | 17/6/2026 | Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | |
| Aplazada | Media (5.5) | 0.21% | — | Bkav HomeAI | 23/4/2024 | 17/6/2026 | Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver. | |
| Aplazada | Alta (8.1) | 0.27% | — | EsphomeAI | 11/4/2024 | 17/6/2026 | ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 2023.12.9 (command line installation) are vulnerable to Cross-Site Request Forgery (CSRF) allowing remote attackers to carry out attacks against a logged user of the… | |
| Analizada | Crítica (9.8) | 0.66% | — | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 Firmware+123 | 1/4/2024 | 17/6/2026 | Memory corruption while redirecting log file to any file location with any file name. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au Firmware+226 | 1/4/2024 | 17/6/2026 | Memory corruption when there is failed unmap operation in GPU. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Apq8064au Firmware+284 | 1/4/2024 | 17/6/2026 | Memory corruption while processing finish_sign command to pass a rsp buffer. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+298 | 1/4/2024 | 17/6/2026 | Memory corruption in SPS Application while requesting for public key in sorter TA. | |
| Aplazada | Alta (7.1) | 0.42% | — | Hometory Mang Board WPAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0. | |
| Modificada | Crítica (9.8) | 1.5% | — | Home-made Fastmag Sync | 25/3/2024 | 9/7/2026 | An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component. | |
| Modificada | Alta (8.8) | 0.50% | — | Inspirythemes Realhomes | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. | |
| Modificada | Alta (8.8) | 0.46% | — | Inspirythemes Realhomes | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. | |
| Analizada | Alta (8.7) | 0.68% | — | Esphome | 6/3/2024 | 17/6/2026 | ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file API in dashboard component of ESPHome version 2023.12.9 (command line installation and Home Assistant add-on) serves unsanitized data with… | |
| Analizada | Crítica (9.8) | 0.35% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+127 | 4/3/2024 | 17/6/2026 | Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE. | |
| Analizada | Crítica (9.8) | 0.35% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+145 | 4/3/2024 | 17/6/2026 | Memory corruption while processing MBSSID beacon containing several subelement IE. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+135 | 4/3/2024 | 17/6/2026 | Memory corruption while processing TPC target power table in FTM TPC. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+133 | 4/3/2024 | 17/6/2026 | Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame. | |
| Analizada | Alta (7.5) | 0.75% | 💥 PoC | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+145 | 4/3/2024 | 17/6/2026 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+309 | 4/3/2024 | 17/6/2026 | Memory corruption in Audio while processing RT proxy port register driver. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+336 | 4/3/2024 | 17/6/2026 | Memory corruption in Core Services while executing the command for removing a single event listener. | |
| Analizada | Alta (8.8) | 1.5% | — | Esphome | 26/2/2024 | 17/6/2026 | ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the configuration directory rendering… | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 14/2/2024 | 17/6/2026 | In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code,… |