Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.12%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1762/9/202417/6/2026
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
AnalizadaMedia (6.7)0.16%—Dell Powerscale Onefs31/8/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access.
AnalizadaMedia (6.3)0.19%—Dell Powerscale Onefs31/8/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
AnalizadaAlta (8.8)0.46%—Wolfssl30/8/202417/6/2026
Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure.
ModificadaAlta (8.8)0.58%—Wolfssl29/8/202417/6/2026
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.
AnalizadaMedia (5.5)0.18%—Wolfssl29/8/202417/6/2026
The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection.…
AnalizadaCrítica (10)0.56%—Wolfssl27/8/202417/6/2026
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a caller was attempting to do a name check on…
AnalizadaMedia (5.1)0.47%—Wolfssl27/8/202417/6/2026
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500
AnalizadaMedia (5.9)0.42%—Wolfssl27/8/202417/6/2026
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success…
ModificadaMedia (4.9)0.35%—Wolfssl27/8/202417/6/2026
Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The division used during the reduction estimates a factor q_e by dividing the upper two digits (a digit having e.g. a size of 8 byte)…
ModificadaCrítica (9.8)0.49%—Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+5431/7/202417/6/2026
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.
ModificadaAlta (7.5)0.56%—Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+5431/7/202417/6/2026
A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
AnalizadaMedia (4.7)0.38%—Oracle ZFS Storage Appliance KIT16/7/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks…
ModificadaMedia (6.7)0.16%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access.
ModificadaMedia (6.7)0.16%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
ModificadaMedia (6.7)0.15%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges.
ModificadaMedia (6.7)0.16%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
ModificadaMedia (6.7)0.16%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation.
ModificadaAlta (7.8)0.16%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
ModificadaAlta (7.5)0.21%—Dell Powerscale Onefs2/7/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks.
ModificadaAlta (7.8)0.10%—Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+3391/7/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition.
ModificadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2551/7/202417/6/2026
Memory corruption while processing key blob passed by the user.
ModificadaMedia (5.5)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+3071/7/202417/6/2026
Transient DOS while loading the TA ELF file.
ModificadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+3091/7/202417/6/2026
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
AplazadaMedia (4.5)0.16%—Ntfs-3gAI13/6/202417/6/2026
NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.