Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+215 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with invalid input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+211 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot OEM commands. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s FirmwareQualcomm Cq8750m Firmware+137 | 1/6/2026 | 22/7/2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+136 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon 480 5G Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 3 Mobile Platform Firmware+261 | 1/6/2026 | 22/7/2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | |
| Aplazada | Crítica (10) | 0.52% | — | Wpswings Gift Cards FOR Woocommerce PROAI | 20/5/2026 | 23/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6. | |
| Analizada | Alta (8.6) | 2.3% | — | Wftpserver Wing FTP Server | 12/5/2026 | 17/6/2026 | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua… | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+172 | 4/5/2026 | 29/6/2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Subscriptions FOR WoocommerceAI | 18/3/2026 | 17/6/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any… | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+184 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4. | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Media (5.1) | 0.20% | — | Wftpserver Wing FTP Server | 7/2/2026 | 17/6/2026 | Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper… | |
| Analizada | Alta (8.5) | 0.25% | — | Wftpserver Wing FTP Server | 5/2/2026 | 17/6/2026 | Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem… | |
| Analizada | Alta (8.6) | 1.2% | — | Wftpserver Wing FTP Server | 30/1/2026 | 17/6/2026 | Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function. | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Media (5.4) | 0.24% | — | Wpswings Points AND Rewards FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce points-and-rewards-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Points and Rewards for WooCommerce: from n/a through <= 2.9.5. | |
| Analizada | Media (5.3) | 0.58% | — | Swingmx Swing Music | 19/1/2026 | 17/6/2026 | Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.… | |
| Analizada | Alta (8.3) | 0.54% | — | Pterodactyl Wings | 19/1/2026 | 17/6/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log entries allowing for low privileged user to trigger a condition that floods the… | |
| Analizada | Alta (8.3) | 0.29% | — | Pterodactyl Wings | 19/1/2026 | 17/6/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an… |