Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.07%—Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+1724/5/202629/6/2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
AnalizadaAlta (7.8)0.12%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 Firmware+164/5/20267/10/2026
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
AnalizadaAlta (7)0.09%—Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+964/5/20267/10/2026
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
AnalizadaMedia (5.5)0.11%—Qualcomm X2000086 FirmwareQualcomm X2000090 FirmwareQualcomm X2000092 FirmwareQualcomm X2000094 Firmware+274/5/20267/10/2026
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
AnalizadaAlta (7.8)0.12%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 FirmwareQualcomm Iqx7181 Firmware+124/5/20267/10/2026
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
AnalizadaAlta (7.8)0.10%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/20267/10/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AnalizadaAlta (7.5)0.18%—Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+2534/5/20267/10/2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
AnalizadaAlta (7.5)0.18%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2414/5/20267/10/2026
Transient DOS when processing target power rate tables during channel configuration.
AnalizadaMedia (6.7)0.15%—Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+284/5/202617/6/2026
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.
AnalizadaMedia (6.5)0.29%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+474/5/202617/6/2026
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;…
AnalizadaMedia (6.5)0.22%—Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+644/5/202617/6/2026
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue…
AnalizadaMedia (6.7)0.15%—Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+184/5/202617/6/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.
AnalizadaMedia (6.7)0.11%—Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+134/5/202617/6/2026
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.
AnalizadaCrítica (9)0.75%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The…
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS…
ModificadaCrítica (9.8)1.00%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.9)0.62%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
ModificadaMedia (6.5)0.50%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
ModificadaAlta (7.5)0.57%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
ModificadaAlta (8.8)3.3%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
AnalizadaBaja (2.1)4.4%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. Once again…
AnalizadaBaja (2.1)4.4%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may…
AnalizadaBaja (2.1)6.0%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and…
AnalizadaMedia (6.3)0.31%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a manipulation results in insufficient verification of data authenticity. The attack is possible to be carried out…