Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.32%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System…
ModificadaMedia (6.5)0.20%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023
ModificadaMedia (6.1)0.33%—Geekcodelab ALL 404 Pages Redirect TO Homepage12/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue affects All 404 Pages Redirect to Homepage: from n/a through 1.9.
ModificadaCrítica (9.8)1.2%—Oaooa Pichome8/2/202417/6/2026
File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.
ModificadaAlta (7.5)0.32%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3056/2/202417/6/2026
Transient DOS while parse fils IE with length equal to 1.
ModificadaAlta (7.5)0.32%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+2346/2/202417/6/2026
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
ModificadaAlta (7.5)0.32%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+1386/2/202417/6/2026
Transient DOS while processing 11AZ RTT management action frame received through OTA.
ModificadaAlta (7.5)0.32%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 Firmware+2826/2/202417/6/2026
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
ModificadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2636/2/202417/6/2026
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
ModificadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2416/2/202417/6/2026
Memory corruption in Core while processing control functions.
ModificadaMedia (4.9)0.82%—Westerndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Mirror G2 Firmware+85/2/202417/6/2026
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My…
ModificadaMedia (5.5)0.24%—Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+95/2/202417/6/2026
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that…
ModificadaCrítica (9.8)0.65%—Kddi Home Spot Cube 2 Firmware2/2/202417/6/2026
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.
ModificadaAlta (7.5)0.65%—Kddi Home Spot Cube 2 Firmware2/2/202417/6/2026
Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported.
ModificadaAlta (7.5)3.6%💥 ExploitEzhometech Ezserver25/1/202417/6/2026
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
ModificadaAlta (7.8)0.16%—Intel NUC 8 Home Nuc8i3behfa FirmwareIntel NUC 8 Home Nuc8i5behfa FirmwareIntel NUC 8 Home Nuc8i5bekpa FirmwareIntel NUC 8 Enthusiast Nuc8i7behga Firmware+919/1/202417/6/2026
Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.98%—Phome Empirecms9/1/202417/6/2026
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
ModificadaCrítica (9.8)0.24%—Google Nest Audio FirmwareGoogle Nest Mini FirmwareGoogle Home Mini FirmwareGoogle Home Firmware2/1/202417/6/2026
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
ModificadaAlta (7.5)0.32%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au Firmware+3522/1/202417/6/2026
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
ModificadaAlta (7.5)0.32%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6900 Firmware+982/1/202417/6/2026
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
ModificadaAlta (7.5)0.34%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3062/1/202417/6/2026
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
ModificadaAlta (7.5)0.34%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2862/1/202417/6/2026
Transient DOS in WLAN Firmware while parsing a BTM request.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+2602/1/202417/6/2026
Memory corruption in Audio during playback with speaker protection.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+2942/1/202417/6/2026
Memory corruption in HLOS while running playready use-case.
ModificadaAlta (7.5)0.30%—Hihonor Magichome29/12/202317/6/2026
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.