Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.23% | — | Fptsoftware Nightwolf Penetration Testing Platform | 13/4/2026 | 7/7/2026 | Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser | |
| Analizada | Alta (7.5) | 0.15% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+99 | 6/4/2026 | 17/6/2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Analizada | Alta (8.8) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 30/9/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+97 | 6/4/2026 | 30/9/2026 | Memory corruption while processing a frame request from user. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+177 | 6/4/2026 | 30/9/2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+160 | 2/3/2026 | 17/6/2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+90 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+184 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Aplazada | Alta (8.8) | 0.19% | — | CGM NetraadAICGM ClininetAI | 2/3/2026 | 17/6/2026 | SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sa9000p FirmwareQualcomm Sar2130p FirmwareQualcomm Snapdragon 8 Gen1 5G FirmwareQualcomm Sd662 Firmware+149 | 2/2/2026 | 17/6/2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration Testing TrackingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration TestingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Media (6.9) | 0.36% | — | Nightwolf Penetration Testing PlatformAINightwolf LogbugAI | 27/3/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows attackers to execute JavaScript through the markdown editor feature. | |
| Modificada | Alta (7.5) | 2.5% | — | 1byte Copy91byte Exactspy1byte Fonetracker1byte Guestspy+5 | 24/2/2022 | 17/6/2026 | The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability. | |
| Modificada | Media (5.4) | 0.62% | — | Phonetrack MEU Site Manager | 16/8/2021 | 17/6/2026 | The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue. | |
| Modificada | Crítica (9.8) | 1.7% | — | Monetra Mstdlib | 13/7/2018 | 17/6/2026 | mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/m_fs_path.c. An attacker could create the file and then would have… | |
| Modificada | Baja (2.1) | 0.36% | — | Oracle SUN Products Suite SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Netra Sparc T4-1+9 | 17/10/2012 | 16/6/2026 | Unspecified vulnerability in the Integrated Lights Out Manager CLI in Oracle Sun Products Suite SysFW 8.2.0.a for SPARC and Netra SPARC T3 and T4-based servers, and other versions and servers, allows local users to affect confidentiality via unknown vectors. | |
| Modificada | Baja (3.7) | 0.34% | — | Oracle Sparc T-series Server FirmwareOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Netra Sparc T4-1+10 | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager. | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1Oracle Sparc T3-1b+15 | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows local users to affect confidentiality, related to Integrated Lights Out Manager CLI. | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1+8 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle SysFW 8.1.0.a in various Oracle SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade servers allows remote attackers to affect confidentiality, integrity, and availability, related to Sun Integrated Lights Out Manager (ILOM). |