Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+176 | 2/9/2024 | 17/6/2026 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | |
| Analizada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 31/8/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access. | |
| Analizada | Media (6.3) | 0.19% | — | Dell Powerscale Onefs | 31/8/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. | |
| Analizada | Alta (8.8) | 0.46% | — | Wolfssl | 30/8/2024 | 17/6/2026 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure. | |
| Modificada | Alta (8.8) | 0.58% | — | Wolfssl | 29/8/2024 | 17/6/2026 | Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure. | |
| Analizada | Media (5.5) | 0.18% | — | Wolfssl | 29/8/2024 | 17/6/2026 | The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection.… | |
| Analizada | Crítica (10) | 0.56% | — | Wolfssl | 27/8/2024 | 17/6/2026 | In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a caller was attempting to do a name check on… | |
| Analizada | Media (5.1) | 0.47% | — | Wolfssl | 27/8/2024 | 17/6/2026 | A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500 | |
| Analizada | Media (5.9) | 0.42% | — | Wolfssl | 27/8/2024 | 17/6/2026 | An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success… | |
| Modificada | Media (4.9) | 0.35% | — | Wolfssl | 27/8/2024 | 17/6/2026 | Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The division used during the reduction estimates a factor q_e by dividing the upper two digits (a digit having e.g. a size of 8 byte)… | |
| Modificada | Crítica (9.8) | 0.49% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+54 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization. | |
| Modificada | Alta (7.5) | 0.56% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+54 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. | |
| Analizada | Media (4.7) | 0.38% | — | Oracle ZFS Storage Appliance KIT | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks… | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | |
| Modificada | Media (6.7) | 0.15% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Alta (7.5) | 0.21% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+339 | 1/7/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+255 | 1/7/2024 | 17/6/2026 | Memory corruption while processing key blob passed by the user. | |
| Modificada | Media (5.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+307 | 1/7/2024 | 17/6/2026 | Transient DOS while loading the TA ELF file. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+309 | 1/7/2024 | 17/6/2026 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. | |
| Aplazada | Media (4.5) | 0.16% | — | Ntfs-3gAI | 13/6/2024 | 17/6/2026 | NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging. |