Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.43%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+1117/11/202317/6/2026
Transient DOS in WLAN Firmware while parsing t2lm buffers.
ModificadaAlta (7.5)0.43%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+1747/11/202317/6/2026
Transient DOS in WLAN Firmware while parsing no-inherit IES.
ModificadaCrítica (9.8)0.47%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 Firmware+1257/11/202317/6/2026
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
ModificadaMedia (5.5)0.14%—Qualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+2047/11/202317/6/2026
Information disclosure in WLAN HAL while handling command through WMI interfaces.
ModificadaMedia (5.5)0.14%—Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+2267/11/202317/6/2026
Information disclosure in IOE Firmware while handling WMI command.
ModificadaMedia (5.5)0.14%—Qualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csr8811 Firmware+1447/11/202317/6/2026
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
ModificadaMedia (5.5)0.14%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+1407/11/202317/6/2026
Information Disclosure in WLAN Host when processing WMI event command.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2677/11/202317/6/2026
Memory Corruption in Core due to secure memory access by user while loading modem image.
ModificadaAlta (7.5)0.45%—Inohom Home Manager Gateway27/10/202317/6/2026
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Account Footprinting. This issue affects Home Manager Gateway: before v.1.27.12.
ModificadaMedia (5.3)0.42%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from the local network. This issue is facilitated by the SniTun proxy, which…
ModificadaMedia (5.4)0.40%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be sent to the URL specified in the aforementioned parameters.…
ModificadaAlta (8.8)0.28%—Home-assistant Home Assistant Companion19/10/202317/6/2026
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may…
ModificadaAlta (7.2)0.46%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An…
ModificadaAlta (7.8)0.17%💥 PoCHome-assistant Home Assistant Companion19/10/202317/6/2026
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution, and credential theft. This issue has…
ModificadaCrítica (9.6)0.95%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative…
ModificadaCrítica (9)0.27%—Home-assistantHome-assistant-js-websocket19/10/202317/6/2026
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized…
ModificadaCrítica (9.6)0.67%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically ensures that it matches the `client_id`…
ModificadaCrítica (9.1)0.37%—Acronis Cyber Protect Home Office4/10/202317/6/2026
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.
ModificadaCrítica (9.8)0.54%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+1723/10/202317/6/2026
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
ModificadaAlta (7.5)0.39%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3243/10/202317/6/2026
Transient DOS in WLAN Firmware while parsing rsn ies.
ModificadaAlta (7.5)0.39%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+1913/10/202317/6/2026
Transient DOS in WLAN Firmware while parsing a NAN management frame.
ModificadaAlta (7.8)0.12%—Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csrb31024 Firmware+1533/10/202317/6/2026
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
ModificadaAlta (7.8)0.12%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2023/10/202317/6/2026
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
ModificadaAlta (7.5)0.39%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2533/10/202317/6/2026
Transient DOS in Modem while allocating DSM items.
ModificadaAlta (7.5)0.35%—Acronis Cyber Protect Home Office20/9/202317/6/2026
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.