Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.3)0.14%—Bizerba Connect.brainAI20/7/202621/7/2026
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or…
Pendiente de análisisMedia (6.8)0.13%—Lenovo Smart ConnectAI16/7/202616/7/2026
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
AplazadaAlta (8.5)0.17%—Eset Inspect ConnectorAI16/7/202616/7/2026
A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel.
Pendiente de análisisCrítica (9.2)0.29%—Snowflake Connector FOR PythonAI16/7/202616/7/2026
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or…
AnalizadaMedia (5.5)0.50%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine15/7/202625/9/2026
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
ModificadaAlta (8.8)0.50%—Microsoft Azure Connected Machine Agent14/7/202618/8/2026
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Pendiente de análisisCrítica (9.2)0.31%—Snowflake Spark ConnectorAI14/7/202615/7/2026
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could…
AplazadaMedia (4.9)0.32%—Catalystconnect Catalyst Connect Zoho CRM Client PortalAI11/7/202629/9/2026
The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaAlta (7.2)0.59%—Connect Contact Form 7 AND MailchimpAI9/7/20269/7/2026
The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AnalizadaCrítica (9.8)0.51%—IBM API Connect8/7/202610/7/2026
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
AnalizadaCrítica (9.8)0.41%—IBM API Connect8/7/202610/7/2026
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
AnalizadaAlta (7)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 Firmware+176/7/20267/7/2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
AnalizadaAlta (8.8)0.11%—Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+1246/7/20267/7/2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+756/7/20267/7/2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
AnalizadaAlta (7.1)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+496/7/20268/7/2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+436/7/20267/7/2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1056/7/20267/7/2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
AnalizadaAlta (7.3)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+446/7/202629/9/2026
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+446/7/202629/9/2026
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+566/7/202629/9/2026
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
En análisisCrítica (9.8)0.41%—UI Unifi Connect2/7/20269/7/2026
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
AnalizadaCrítica (10)1.7%💥 PoCUI Unifi Connect Application2/7/202629/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
AplazadaAlta (7.7)0.38%—PretixAIPretix MollieAIPretix OppwaAIPretix BitpayAI+51/7/20262/7/2026
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and…