Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca2062 Firmware+16 | 2/12/2024 | 17/6/2026 | Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+87 | 2/12/2024 | 17/6/2026 | Memory corruption while processing API calls to NPU with invalid input. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+50 | 2/12/2024 | 17/6/2026 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2073 Firmware+15 | 2/12/2024 | 17/6/2026 | Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm4325 Firmware+48 | 2/12/2024 | 17/6/2026 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform Firmware+120 | 2/12/2024 | 17/6/2026 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+325 | 2/12/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | |
| Analizada | Media (6.7) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+52 | 2/12/2024 | 17/6/2026 | Memory corruption when multiple threads try to unregister the CVP buffer at the same time. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csrb31024 Firmware+207 | 2/12/2024 | 17/6/2026 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | |
| Analizada | Alta (7) | 0.09% | — | Qualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p Firmware+26 | 2/12/2024 | 17/6/2026 | Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access. | |
| Analizada | Media (6.1) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Qam8295p Firmware+47 | 2/12/2024 | 17/6/2026 | Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. | |
| Analizada | Media (6.7) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+48 | 2/12/2024 | 17/6/2026 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | |
| Aplazada | Media (6.4) | 0.40% | — | Login With Vipps AND MobilepayAI | 28/11/2024 | 17/6/2026 | The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7) | 0.10% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Ar6003 FirmwareQualcomm Snapdragon 630 Mobile Firmware+1 | 26/11/2024 | 17/6/2026 | A race condition exists in a driver potentially leading to a use-after-free condition. | |
| Aplazada | Media (6.5) | 0.39% | — | Figoliquinn Mobile KioskAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in figoliquinn Mobile Kiosk mobile-kiosk allows Stored XSS.This issue affects Mobile Kiosk: from n/a through <= 1.3.0. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Anthony Carbon Wdes Responsive Mobile MenuAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through <= 5.3.18. | |
| Modificada | Alta (7.5) | 0.45% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Modificada | Crítica (9.8) | 0.51% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Snapdragon W5+ GEN 1 Wearable Platform FirmwareQualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 8+ GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform (sm4350-ac) Firmware+115 | 4/11/2024 | 17/6/2026 | Memory corruption during GNSS HAL process initialization. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 FirmwareQualcomm Wsa8810 Firmware+202 | 4/11/2024 | 17/6/2026 | Memory corruption while processing GPU page table switch. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+264 | 4/11/2024 | 17/6/2026 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+73 | 4/11/2024 | 17/6/2026 | Memory corruption while processing GPU commands. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+144 | 4/11/2024 | 17/6/2026 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+174 | 4/11/2024 | 17/6/2026 | Memory corruption while handling session errors from firmware. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+21 | 4/11/2024 | 17/6/2026 | Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice. |