Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+172 | 4/5/2026 | 29/6/2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 Firmware+16 | 4/5/2026 | 7/10/2026 | Memory corruption when another driver calls an IOCTL with invalid input/output buffer. | |
| Analizada | Alta (7) | 0.09% | — | Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+96 | 4/5/2026 | 7/10/2026 | Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm X2000086 FirmwareQualcomm X2000090 FirmwareQualcomm X2000092 FirmwareQualcomm X2000094 Firmware+27 | 4/5/2026 | 7/10/2026 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Iqx5121 FirmwareQualcomm Iqx7181 Firmware+12 | 4/5/2026 | 7/10/2026 | Memory corruption when processing camera sensor input/output control codes with invalid output buffers. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 7/10/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 7/10/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 7/10/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+28 | 4/5/2026 | 17/6/2026 | In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504. | |
| Analizada | Media (6.5) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+47 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;… | |
| Analizada | Media (6.5) | 0.22% | — | Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+64 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue… | |
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+18 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. | |
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+13 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. | |
| Analizada | Crítica (9) | 0.75% | — | Geovision Gv-vms Firmware | 4/5/2026 | 17/6/2026 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The… | |
| Analizada | Media (6.1) | 0.34% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS… | |
| Modificada | Crítica (9.8) | 1.00% | — | Geovision Gv-vms Firmware | 4/5/2026 | 17/6/2026 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 0.62% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.50% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.57% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.3% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability. | |
| Analizada | Baja (2.1) | 4.4% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. Once again… | |
| Analizada | Baja (2.1) | 4.4% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Baja (2.1) | 6.0% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (6.3) | 0.31% | — | Trendnet Tew-821dap Firmware | 2/5/2026 | 17/6/2026 | A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a manipulation results in insufficient verification of data authenticity. The attack is possible to be carried out… |