Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Qcn9070 FirmwareQualcomm Qcn9072 FirmwareQualcomm Qcn9074 FirmwareQualcomm Qcn9100 Firmware+265 | 7/4/2025 | 17/6/2026 | Transient DOS may occur while parsing SSID in action frames. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+145 | 7/4/2025 | 17/6/2026 | Transient DOS may occur while parsing extended IE in beacon. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform Firmware+56 | 7/4/2025 | 17/6/2026 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+306 | 7/4/2025 | 17/6/2026 | There may be information disclosure during memory re-allocation in TZ Secure OS. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Qcn6224 FirmwareQualcomm Qcn6274 FirmwareQualcomm Qcn6402 FirmwareQualcomm Qcn6412 Firmware+149 | 3/3/2025 | 17/6/2026 | Memory corruption while processing command in Glink linux. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Crítica (9.8) | 0.29% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+182 | 3/2/2025 | 17/6/2026 | Memory corruption during management frame processing due to mismatch in T2LM info element. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+146 | 3/2/2025 | 17/6/2026 | Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. | |
| Analizada | Crítica (9.8) | 0.58% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+170 | 3/2/2025 | 17/6/2026 | Memory corruption while parsing the ML IE due to invalid frame content. | |
| Analizada | Media (4.4) | 0.13% | — | Dell Vxrail D560 FirmwareDell Vxrail D560f FirmwareDell Vxrail E460 FirmwareDell Vxrail E560 Firmware+38 | 8/1/2025 | 17/6/2026 | Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (4.4) | 0.17% | — | Dell Vxrail D560 FirmwareDell Vxrail D560f FirmwareDell Vxrail E460 FirmwareDell Vxrail E560 Firmware+38 | 8/1/2025 | 17/6/2026 | Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.5) | 0.36% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+179 | 6/1/2025 | 17/6/2026 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform Firmware+120 | 2/12/2024 | 17/6/2026 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+325 | 2/12/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | |
| Analizada | Media (4.8) | 0.35% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Crítica (9.8) | 0.62% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | |
| Analizada | Alta (8.1) | 0.46% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs. | |
| Analizada | Media (5.3) | 0.55% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests. | |
| Analizada | Alta (7.5) | 0.71% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 Firmware+112 | 7/10/2024 | 17/6/2026 | Transient DOS while parsing probe response and assoc response frame. |