Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3) | 0.18% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version… | |
| Analizada | Media (6.8) | 0.32% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixed in version… | |
| Analizada | Media (5.9) | 0.34% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (5.9 Medium). This… | |
| Analizada | Baja (2.7) | 0.33% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N (2.7 Low). This… | |
| Analizada | Media (5.8) | 0.33% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed… | |
| Analizada | Alta (8.4) | 0.40% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version 4.0.260202.0 of the… | |
| Analizada | Media (6.4) | 0.34% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H (6.4… | |
| Analizada | Baja (2.1) | 0.28% | — | Parseplatform Parse-server | 6/4/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g.,… | |
| Analizada | Alta (7.5) | 0.15% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+99 | 6/4/2026 | 17/6/2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca0000 Firmware+19 | 6/4/2026 | 17/6/2026 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcd9375 FirmwareQualcomm Wcd9378c FirmwareQualcomm Wcd9380 FirmwareQualcomm Wcd9385 Firmware+47 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcn3988 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8835 Firmware+31 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sm6250 FirmwareQualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Snapdragon 7C Compute Platform Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm X2000094 FirmwareQualcomm Xg101002 FirmwareQualcomm Xg101032 FirmwareQualcomm Xg101039 Firmware+24 | 6/4/2026 | 17/6/2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Snapdragon 8CX Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware+48 | 6/4/2026 | 17/6/2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Analizada | Alta (8.8) | 0.28% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 7/10/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+97 | 6/4/2026 | 7/10/2026 | Memory corruption while processing a frame request from user. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Qcm5430 FirmwareQualcomm Qcm6490 FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Sc8380xp Firmware+25 | 6/4/2026 | 7/10/2026 | Memory corruption while preprocessing IOCTL request in JPEG driver. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+177 | 6/4/2026 | 7/10/2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | |
| Analizada | Media (6.5) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+26 | 6/4/2026 | 7/10/2026 | Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling. | |
| Aplazada | Baja (2.1) | 0.34% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Baja (2.9) | 0.39% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded… |