Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3953 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3)0.18%—Runzero Platform7/4/202617/6/2026
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version…
AnalizadaMedia (6.8)0.32%—Runzero Platform7/4/202617/6/2026
An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixed in version…
AnalizadaMedia (5.9)0.34%—Runzero Platform7/4/202617/6/2026
An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (5.9 Medium). This…
AnalizadaBaja (2.7)0.33%—Runzero Platform7/4/202617/6/2026
An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N (2.7 Low). This…
AnalizadaMedia (5.8)0.33%—Runzero Platform7/4/202617/6/2026
An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed…
AnalizadaAlta (8.4)0.40%—Runzero Platform7/4/202617/6/2026
An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version 4.0.260202.0 of the…
AnalizadaMedia (6.4)0.34%—Runzero Platform7/4/202617/6/2026
An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H (6.4…
AnalizadaBaja (2.1)0.28%—Parseplatform Parse-server6/4/202624/7/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g.,…
AnalizadaAlta (7.5)0.15%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+996/4/202617/6/2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
AnalizadaAlta (7.8)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca0000 Firmware+196/4/202617/6/2026
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
AnalizadaAlta (7.8)0.07%—Qualcomm Wcd9375 FirmwareQualcomm Wcd9378c FirmwareQualcomm Wcd9380 FirmwareQualcomm Wcd9385 Firmware+476/4/202617/6/2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+506/4/202617/6/2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
AnalizadaAlta (7.8)0.07%—Qualcomm Wcn3988 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8835 Firmware+316/4/202617/6/2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
AnalizadaAlta (7.8)0.11%—Qualcomm Sm6250 FirmwareQualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Snapdragon 7C Compute Platform Firmware+506/4/202617/6/2026
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+506/4/202617/6/2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
AnalizadaAlta (7.8)0.10%—Qualcomm X2000094 FirmwareQualcomm Xg101002 FirmwareQualcomm Xg101032 FirmwareQualcomm Xg101039 Firmware+246/4/202617/6/2026
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
AnalizadaAlta (7.8)0.10%—Qualcomm Snapdragon 8CX Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware+486/4/202617/6/2026
Memory Corruption when retrieving output buffer with insufficient size validation.
AnalizadaAlta (7.5)0.20%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+1466/4/202617/6/2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
AnalizadaAlta (8.8)0.28%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/20267/10/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
AnalizadaAlta (7.8)0.16%—Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+976/4/20267/10/2026
Memory corruption while processing a frame request from user.
AnalizadaAlta (7.8)0.16%—Qualcomm Qcm5430 FirmwareQualcomm Qcm6490 FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Sc8380xp Firmware+256/4/20267/10/2026
Memory corruption while preprocessing IOCTL request in JPEG driver.
AnalizadaAlta (7.8)0.16%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1776/4/20267/10/2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
AnalizadaMedia (6.5)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+266/4/20267/10/2026
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
AplazadaBaja (2.1)0.34%—Hcengineering Huly PlatformAI6/4/202624/7/2026
A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used.…
AplazadaBaja (2.9)0.39%—Hcengineering Huly PlatformAI6/4/202624/7/2026
A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded…