Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 Firmware+344 | 22/2/2021 | 17/6/2026 | Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+336 | 22/2/2021 | 17/6/2026 | Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | |
| Modificada | Alta (8.8) | 0.29% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+533 | 22/2/2021 | 17/6/2026 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | |
| Modificada | Alta (7.8) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Pm3003a FirmwareQualcomm Pm456 FirmwareQualcomm Pm6150 Firmware+198 | 22/2/2021 | 17/6/2026 | Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | |
| Modificada | Alta (7.8) | 0.17% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+515 | 22/2/2021 | 17/6/2026 | Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | |
| Modificada | Crítica (9.8) | 0.83% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8030 Firmware+501 | 22/2/2021 | 17/6/2026 | Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | |
| Modificada | Media (6.7) | 0.16% | — | Qualcomm Aqt1000 FirmwareQualcomm Pm3003a FirmwareQualcomm Pm456 FirmwareQualcomm Pm6125 Firmware+199 | 22/2/2021 | 17/6/2026 | Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile | |
| Modificada | Crítica (9.8) | 2.1% | — | Tp-link M7350 Firmware | 24/10/2019 | 17/6/2026 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5). | |
| Modificada | Crítica (9.8) | 2.8% | — | Tp-link M7350 Firmware | 24/10/2019 | 17/6/2026 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5). | |
| Modificada | Crítica (9.8) | 3.0% | — | Tp-link M7350 Firmware | 24/10/2019 | 17/6/2026 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5). | |
| Modificada | Crítica (9.8) | 2.8% | — | Tp-link M7350 Firmware | 24/10/2019 | 17/6/2026 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5). | |
| Modificada | Crítica (9.8) | 2.8% | — | Tp-link M7350 Firmware | 24/10/2019 | 17/6/2026 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5). | |
| Modificada | Alta (8.8) | 4.6% | — | Tp-link M7350 Firmware | 14/8/2019 | 17/6/2026 | The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities. | |
| Modificada | Crítica (9.8) | 3.4% | — | Tp-link M7350 Firmware | 14/8/2019 | 17/6/2026 | The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulnerability. |