Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

933 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2053/6/202417/6/2026
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+1333/6/202417/6/2026
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
AnalizadaAlta (8.8)77%💥 PoCZabbix17/5/202417/6/2026
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
AnalizadaMedia (6.5)0.71%—ABB Robotware14/5/202417/6/2026
An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is…
AnalizadaAlta (7.6)0.69%—ABB Robotware14/5/202417/6/2026
An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when…
AnalizadaAlta (7.8)0.13%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+446/5/202417/6/2026
Memory corruption when the channel ID passed by user is not validated and further used.
AnalizadaAlta (7.8)0.11%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p Firmware+206/5/202417/6/2026
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1546/5/202417/6/2026
Memory corruption in HLOS while checking for the storage type.
AnalizadaAlta (7)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1576/5/202417/6/2026
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
AplazadaAlta (7.2)0.66%—ABB Rtu500AI30/4/202417/6/2026
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
AplazadaMedia (5.4)0.32%—Softlabbd Radio PlayerAI25/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AplazadaMedia (5.4)0.35%—Softlabbd Radio PlayerAI17/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AplazadaAlta (7.5)0.61%—ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI3/4/202417/6/2026
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,…
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+291/4/202417/6/2026
Memory corruption while allocating memory for graphics.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1641/4/202417/6/2026
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Apq8064au Firmware+2841/4/202417/6/2026
Memory corruption while processing finish_sign command to pass a rsp buffer.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+2981/4/202417/6/2026
Memory corruption in SPS Application while requesting for public key in sorter TA.
AplazadaCrítica (10)0.73%—Softlabbd Integrate Google DriveAI30/3/202417/6/2026
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up…
ModificadaMedia (5.4)0.34%—Softlabbd Radio Player27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.
AplazadaMedia (6.8)0.57%—ABB Rtu500AI27/3/202417/6/2026
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.
AplazadaAlta (8.2)0.45%—ABB Rtu500AI27/3/202417/6/2026
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.
AplazadaMedia (6.5)0.48%—Softlabbd Radio PlayerAI26/3/202417/6/2026
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+294/3/202417/6/2026
Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.
AnalizadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3364/3/202417/6/2026
Memory corruption in Core Services while executing the command for removing a single event listener.
ModificadaMedia (5.4)0.73%—Zabbix9/2/202417/6/2026
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.