Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.35% | — | Wanzhou Woes Intelligent Optimization Energy Saving System | 8/8/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the file /CommonSolution/GetVariableByOneIDNew of the component Historical Data Query Module. The manipulation of the argument ObjectID leads to sql injection. It is… | |
| Analizada | Baja (2.1) | 0.35% | — | Wanzhou Woes Intelligent Optimization Energy Saving System | 7/8/2025 | 17/6/2026 | A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /OL_OprationLog/GetPageList. The manipulation of the argument optUser leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+368 | 6/8/2025 | 17/6/2026 | Transient DOS while processing an ANQP message. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+345 | 6/8/2025 | 17/6/2026 | Information disclosure while processing the hash segment in an MBN file. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+338 | 6/8/2025 | 17/6/2026 | Information disclosure while reading data from an image using specified offset and size parameters. | |
| Aplazada | Alta (7.4) | 1.1% | — | Jointelli 5G CPE 21h01AI | 5/8/2025 | 17/6/2026 | Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with root privileges via… | |
| Modificada | Alta (7.3) | 0.37% | — | Intelbras RX 1500 FirmwareIntelbras RX 3000 Firmware | 4/8/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a visiting Wi-Fi network. | |
| Modificada | Baja (1.3) | 0.28% | — | Intelbras Incontrol WEB | 4/8/2025 | 17/6/2026 | A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this… | |
| Modificada | Alta (7.3) | 0.99% | — | Intelbras RX 1500 FirmwareIntelbras RX 3000 Firmware | 31/7/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Intelbras RX 1500 FirmwareIntelbras RX 3000 Firmware | 31/7/2025 | 17/6/2026 | An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Intelbras RX 1500 FirmwareIntelbras RX 3000 Firmware | 31/7/2025 | 17/6/2026 | An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings. | |
| Analizada | Baja (2.4) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities. | |
| Analizada | Media (4.8) | 0.14% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit. | |
| Analizada | Media (5.7) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks. | |
| Analizada | Media (4.9) | 0.18% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks. | |
| Analizada | Media (5.9) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization. | |
| Analizada | Media (5.3) | 0.37% | — | Cisco Unified Intelligence CenterCisco Unified Contact Center Express | 16/7/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker… | |
| Analizada | Alta (8.8) | 0.44% | — | Cisco Unified Intelligence CenterCisco Unified Contact Center Express | 16/7/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Business Intelligence | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | |
| Analizada | Alta (7.5) | 0.23% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+207 | 8/7/2025 | 17/6/2026 | Transient DOS while handling beacon frames with invalid IE header length. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+152 | 8/7/2025 | 17/6/2026 | Memory corruption while processing data packets in diag received from Unix clients. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption while processing video packets received from video firmware. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sa8620p FirmwareQualcomm Sa8650p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa8775p Firmware+188 | 8/7/2025 | 17/6/2026 | Transient DOS while processing received beacon frame. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+181 | 8/7/2025 | 17/6/2026 | Transient DOS may occur while processing malformed length field in SSID IEs. |