Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+205 | 3/6/2024 | 17/6/2026 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+133 | 3/6/2024 | 17/6/2026 | Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. | |
| Analizada | Alta (8.8) | 77% | 💥 PoC | Zabbix | 17/5/2024 | 17/6/2026 | Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection. | |
| Analizada | Media (6.5) | 0.71% | — | ABB Robotware | 14/5/2024 | 17/6/2026 | An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is… | |
| Analizada | Alta (7.6) | 0.69% | — | ABB Robotware | 14/5/2024 | 17/6/2026 | An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when… | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+44 | 6/5/2024 | 17/6/2026 | Memory corruption when the channel ID passed by user is not validated and further used. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p Firmware+20 | 6/5/2024 | 17/6/2026 | Memory corruption when size of buffer from previous call is used without validation or re-initialization. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+154 | 6/5/2024 | 17/6/2026 | Memory corruption in HLOS while checking for the storage type. | |
| Analizada | Alta (7) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+157 | 6/5/2024 | 17/6/2026 | Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. | |
| Aplazada | Alta (7.2) | 0.66% | — | ABB Rtu500AI | 30/4/2024 | 17/6/2026 | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware. | |
| Aplazada | Media (5.4) | 0.32% | — | Softlabbd Radio PlayerAI | 25/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (5.4) | 0.35% | — | Softlabbd Radio PlayerAI | 17/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Alta (7.5) | 0.61% | — | ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI | 3/4/2024 | 17/6/2026 | ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,… | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+29 | 1/4/2024 | 17/6/2026 | Memory corruption while allocating memory for graphics. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+164 | 1/4/2024 | 17/6/2026 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Apq8064au Firmware+284 | 1/4/2024 | 17/6/2026 | Memory corruption while processing finish_sign command to pass a rsp buffer. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+298 | 1/4/2024 | 17/6/2026 | Memory corruption in SPS Application while requesting for public key in sorter TA. | |
| Aplazada | Crítica (10) | 0.73% | — | Softlabbd Integrate Google DriveAI | 30/3/2024 | 17/6/2026 | The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up… | |
| Modificada | Media (5.4) | 0.34% | — | Softlabbd Radio Player | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (6.8) | 0.57% | — | ABB Rtu500AI | 27/3/2024 | 17/6/2026 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file. | |
| Aplazada | Alta (8.2) | 0.45% | — | ABB Rtu500AI | 27/3/2024 | 17/6/2026 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file. | |
| Aplazada | Media (6.5) | 0.48% | — | Softlabbd Radio PlayerAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+29 | 4/3/2024 | 17/6/2026 | Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+336 | 4/3/2024 | 17/6/2026 | Memory corruption in Core Services while executing the command for removing a single event listener. | |
| Modificada | Media (5.4) | 0.73% | — | Zabbix | 9/2/2024 | 17/6/2026 | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. |