Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.42% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Apq8076 Firmware+291 | 12/2/2023 | 17/6/2026 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+239 | 12/2/2023 | 17/6/2026 | Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Apq8096au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+241 | 12/2/2023 | 17/6/2026 | Information disclosure due to buffer over-read in WLAN while parsing NMF frame. | |
| Modificada | Alta (7.8) | 0.13% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+158 | 12/2/2023 | 17/6/2026 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Apq8096au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 Firmware+153 | 12/2/2023 | 17/6/2026 | Memory corruption due to improper access control in Qualcomm IPC. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+197 | 12/2/2023 | 17/6/2026 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Media (6.5) | 0.74% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell EMC Vasa Provider Virtual Appliance+4 | 18/1/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system. | |
| Modificada | Media (5.5) | 0.21% | — | AMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3200g FirmwareAMD Ryzen 3 3200u FirmwareAMD Ryzen 3 3250c Firmware+100 | 11/1/2023 | 17/6/2026 | Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. | |
| Modificada | Media (5.4) | 0.47% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 9/1/2023 | 17/6/2026 | The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.8) | 0.70% | — | Qualcomm Apq8064au FirmwareQualcomm Apq8096au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+143 | 9/1/2023 | 17/6/2026 | Memory corruption due to stack-based buffer overflow in Core | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 Firmware+189 | 9/1/2023 | 17/6/2026 | Information disclosure due to buffer overread in Core | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+156 | 9/1/2023 | 17/6/2026 | Information disclosure due to buffer overread in Core | |
| Modificada | Alta (7.8) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 Firmware+177 | 9/1/2023 | 17/6/2026 | Memory corruption in core due to stack-based buffer overflow | |
| Modificada | Alta (7.8) | 0.87% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 Firmware+180 | 9/1/2023 | 17/6/2026 | Memory corruption in Core due to stack-based buffer overflow. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8096au FirmwareQualcomm Ar8031 FirmwareQualcomm Csra6620 Firmware+40 | 9/1/2023 | 17/6/2026 | Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8096au FirmwareQualcomm Ar8031 FirmwareQualcomm Csra6620 Firmware+42 | 9/1/2023 | 17/6/2026 | Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. | |
| Modificada | Media (6.5) | 0.38% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Apq8076 Firmware+277 | 9/1/2023 | 17/6/2026 | Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. | |
| Modificada | Media (6.5) | 0.38% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Apq8076 Firmware+274 | 9/1/2023 | 17/6/2026 | Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |