Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 30/9/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 30/9/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Analizada | Crítica (9.6) | 0.32% | — | HPE Aruba Networking Private 5G Core | 7/4/2026 | 17/6/2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled… | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Social Networking SiteAI | 27/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Social Networking SiteAI | 27/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly… | |
| Analizada | Baja (2.3) | 0.19% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the… | |
| Analizada | Media (6.5) | 0.38% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an… | |
| Aplazada | Alta (7.8) | 0.15% | — | HPE Aruba Networking Clearpass OnguardAI | 18/2/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Analizada | Media (6.5) | 0.32% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.30% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… | |
| Analizada | Media (5.5) | 0.38% | — | Code-projects Social Networking Site | 7/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Aplazada | Alta (7.5) | 0.72% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory. | |
| Aplazada | Alta (7.2) | 0.88% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Aplazada | Alta (7.8) | 0.17% | — | HPE Aruba Networking Virtual Intranet AccessAI | 13/1/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Modificada | Alta (7.5) | 0.42% | — | Opennetworking UPF | 18/12/2025 | 5/7/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsing, parseFAR() calls… | |
| Analizada | Alta (7.5) | 0.41% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flow-Description… | |
| Analizada | Alta (7.5) | 0.41% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. The session… | |
| Analizada | Alta (7.5) | 0.43% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer via… | |
| Analizada | Alta (7.5) | 0.44% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferences a nil pointer… | |
| Analizada | Baja (2.1) | 0.35% | — | Fabian Nero Social Networking Site | 17/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Nero Social Networking Site | 17/11/2025 | 17/6/2026 | A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |