Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Foldingathome Client Advanced Control | 11/8/2023 | 17/6/2026 | An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC KIT Nuc7i7bnhx1 FirmwareIntel NUC 7 Home Nuc7i5bnkp FirmwareIntel NUC 7 Home Nuc7i3bnhxf FirmwareIntel NUC 7 Enthusiast Nuc7i7bnkq Firmware+19 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.6) | 0.43% | — | Taphome Core Firmware | 17/7/2023 | 17/6/2026 | An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access… | |
| Modificada | Alta (8.8) | 0.56% | — | Taphome Core Firmware | 17/7/2023 | 17/6/2026 | A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using this vulnerability. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar9380 FirmwareQualcomm C-v2x 9150 Firmware+195 | 4/7/2023 | 17/6/2026 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+159 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+187 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI response message from firmware. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+201 | 4/7/2023 | 17/6/2026 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 4/7/2023 | 17/6/2026 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+197 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. | |
| Modificada | Alta (7.5) | 0.59% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+8 | 12/6/2023 | 17/6/2026 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;… | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+111 | 6/6/2023 | 17/6/2026 | Transient DOS while parsing WLAN beacon or probe-response frame. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Csr8811 FirmwareQualcomm Wcn6750 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+75 | 6/6/2023 | 17/6/2026 | Transient DOS in WLAN Firmware while parsing FT Information Elements. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+266 | 6/6/2023 | 17/6/2026 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Wcn6750 Firmware+147 | 6/6/2023 | 17/6/2026 | Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Apq8076 FirmwareQualcomm Apq8092 Firmware+279 | 6/6/2023 | 17/6/2026 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | |
| Modificada | Alta (7.8) | 1.3% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+238 | 6/6/2023 | 17/6/2026 | Memory corruption due to double free in Core while mapping HLOS address to the list. | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+344 | 6/6/2023 | 17/6/2026 | information disclosure due to cryptographic issue in Core during RPMB read request. | |
| Modificada | Alta (7.5) | 0.29% | — | Agshome Smart Alarm Project Agshome Smart Alarm Firmware | 24/5/2023 | 17/6/2026 | Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack. | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Phpgurukul OLD AGE Home Management System | 23/5/2023 | 17/6/2026 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | |
| Modificada | Media (4.9) | 0.77% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,… | |
| Modificada | Crítica (9.8) | 1.5% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western… | |
| Modificada | Media (4.9) | 0.57% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My… | |
| Modificada | Alta (7.8) | 0.12% | — | Acronis Cyber Protect Home Office | 18/5/2023 | 17/6/2026 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208. | |
| Modificada | Media (6.1) | 0.45% | — | Gira Home Server Firmware | 16/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affects unknown code of the file /hslist. The manipulation of the argument lst with the input debug%27"><img%20src=x%20onerror=alert(document.cookie)> leads to cross site scripting. The attack can be… |