Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. | |
| Analizada | Media (6.8) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.5) | 0.22% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 26/9/2026 | Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.3) | 0.32% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.64% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 26/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.9) | 0.55% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially… | |
| Analizada | Media (6.1) | 0.18% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |
| Analizada | Alta (8.6) | 0.66% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this… | |
| Pendiente de análisis | Media (6.4) | 0.32% | — | Amazon-connect-salesforce-lambdaAI | 22/9/2026 | 22/9/2026 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that… | |
| Aplazada | Alta (8.2) | 0.44% | — | Ansible Freebsd Jail Connection PluginAI | 21/9/2026 | 24/9/2026 | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic… | |
| Pendiente de análisis | Baja (3.7) | 0.37% | — | Mariadb Connector JAI | 17/9/2026 | 23/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL… | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+71 | 17/9/2026 | 22/9/2026 | Transient DOS while parsing frame during channel usage. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Snapdragon X2 Elite FirmwareQualcomm Wcd9378c Firmware+3 | 17/9/2026 | 22/9/2026 | Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | |
| Analizada | Alta (7.3) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Snapdragon X2 Elite FirmwareQualcomm Wcd9378c Firmware+3 | 17/9/2026 | 22/9/2026 | Information Disclosure when a pointer is reused after being deallocated. | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Snapdragon X2 Elite FirmwareQualcomm Wcd9378c Firmware+3 | 17/9/2026 | 22/9/2026 | Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | |
| Analizada | Alta (7.9) | 0.06% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Snapdragon X2 Elite FirmwareQualcomm Wcd9378c Firmware+3 | 17/9/2026 | 22/9/2026 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Snapdragon X2 Elite FirmwareQualcomm Wcd9378c Firmware+3 | 17/9/2026 | 22/9/2026 | Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wsa8845h FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+16 | 17/9/2026 | 22/9/2026 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+20 | 17/9/2026 | 22/9/2026 | Memory corruption while processing rear sensor IOCTL calls. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+148 | 17/9/2026 | 22/9/2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |
| Analizada | Alta (7) | 0.06% | — | Qualcomm Wsa8845h FirmwareQualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 Firmware+39 | 17/9/2026 | 22/9/2026 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. |