Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.2)0.18%—MI 5S Plus FirmwareSony Xperia Z4 FirmwareSamsung Galaxy S6 Edge FirmwareSamsung Galaxy S4 Firmware+46/6/201917/6/2026
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.
ModificadaMedia (5.9)1.1%—Arrow-kt Arrow22/4/201917/6/2026
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
ModificadaMedia (4.6)0.34%—Fujitsu Arrows ME F-11d5/12/201417/6/2026
Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via unknown vectors.
ModificadaAlta (7.2)0.44%—Fujitsu Arrows Kiss F-03dFujitsu Arrows TAB LTE F-01dFujitsu F-12cFujitsu Regza Phone T-01d5/12/201417/6/2026
FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors.
ModificadaMedia (4.6)0.38%—Disney Interactive Disney MobileFujitsu Arrows TAB LTE F-01dSharp Softbank 102shFujitsu Regza Phone T-01d+25/12/201417/6/2026
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary…
ModificadaAlta (10)3.8%—Xarrow25/5/201216/6/2026
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)4.5%—Xarrow25/5/201216/6/2026
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.
ModificadaAlta (10)3.9%—Xarrow25/5/201216/6/2026
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.
ModificadaAlta (7.8)2.2%—Xarrow25/5/201216/6/2026
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.
ModificadaAlta (7.5)6.3%—Tomahawk Technologies Steelarrow11/4/200316/6/2026
Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding…
ModificadaBaja (2.1)0.29%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
ModificadaBaja (2.1)0.52%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.