Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.23% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 FirmwareQualcomm Mdm9650 Firmware+18 | 26/11/2024 | 17/6/2026 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. | |
| Analizada | Crítica (9.8) | 0.35% | — | Qualcomm Msm8909w FirmwareQualcomm Msm8996au FirmwareQualcomm SD 210 FirmwareQualcomm SD 212 Firmware+23 | 26/11/2024 | 17/6/2026 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. | |
| Analizada | Media (6.7) | 0.12% | — | Qualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 FirmwareQualcomm Wsa8810 Firmware+80 | 22/11/2024 | 17/6/2026 | Possible out of bound access in audio module due to lack of validation of user provided input. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 FirmwareQualcomm Mdm9650 Firmware+19 | 22/11/2024 | 17/6/2026 | Certain unprivileged processes are able to perform IOCTL calls. | |
| Analizada | Media (4.8) | 0.35% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Crítica (9.8) | 0.62% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | |
| Analizada | Alta (8.1) | 0.46% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs. | |
| Analizada | Media (5.3) | 0.55% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests. | |
| Analizada | Alta (7.5) | 0.71% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Memory corruption when Alternative Frequency offset value is set to 255. | |
| Analizada | Media (6.5) | 0.52% | — | Tenda Fh1205 Firmware | 17/4/2024 | 17/6/2026 | Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function. | |
| Analizada | Alta (7.4) | 0.59% | — | Tenda Fh1205 Firmware | 17/4/2024 | 17/6/2026 | Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function. | |
| Analizada | Media (6.5) | 0.53% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function. | |
| Analizada | Media (6.5) | 0.53% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function. | |
| Analizada | Media (4.3) | 0.45% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function. | |
| Analizada | Crítica (9.8) | 0.81% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function. | |
| Analizada | Media (5.7) | 0.52% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function. | |
| Modificada | Crítica (9.8) | 0.81% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function. | |
| Analizada | Alta (8.8) | 0.78% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function. | |
| Analizada | Alta (8) | 0.70% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function. | |
| Analizada | Alta (8) | 0.70% | — | Tenda Fh1205 Firmware | 29/3/2024 | 17/6/2026 | Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function. |