Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

3834 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.08%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2718/7/202517/6/2026
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
AnalizadaAlta (8.2)0.22%—Qualcomm Sm6250 FirmwareQualcomm Sm6370 FirmwareQualcomm Sm7315 FirmwareQualcomm Sm7325p Firmware+1758/7/202517/6/2026
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2178/7/202517/6/2026
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1858/7/202517/6/2026
Memory corruption while operating the mailbox in Automotive.
AplazadaMedia (4.1)0.26%—SAP Businessobjects Business Intelligence PlatformAISAP WEB IntelligenceAI8/7/202517/6/2026
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application behavior, such as redirecting users to…
AnalizadaBaja (2)0.34%—Intelbras Incontrol WEB4/7/202517/6/2026
A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (6.5)0.35%—Intelbras RX 1500 Firmware1/7/202517/6/2026
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation function.
AnalizadaMedia (5.3)9.9%—Intelbras RX 1500 Firmware1/7/202517/6/2026
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.
AnalizadaBaja (2.1)0.44%—Intelbras Incontrol WEB27/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been…
AplazadaAlta (8.8)0.36%—Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+124/6/202517/6/2026
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for…
AnalizadaMedia (5.3)0.25%—SAP Businessobjects Business Intelligence Platform10/6/202517/6/2026
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable the researcher to cause SSRF. It has no impact on integrity and…
AnalizadaAlta (7.6)0.36%—SAP Businessobjects Business Intelligence10/6/202517/6/2026
SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make…
AnalizadaMedia (6.7)0.18%—Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+44/6/202517/6/2026
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An…
AnalizadaMedia (6.1)0.27%—Cisco Unified Intelligent Contact Management Enterprise4/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to…
AnalizadaAlta (7.5)0.23%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+2073/6/202517/6/2026
Transient DOS while processing the EHT operation IE in the received beacon frame.
AnalizadaAlta (8.2)0.30%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2213/6/202517/6/2026
Information disclosure may occur while processing goodbye RTCP packet from network.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1893/6/202517/6/2026
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
AplazadaMedia (6.3)0.44%—Intellian C700AI23/5/202517/6/2026
The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail.…
AnalizadaMedia (4.3)0.35%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express21/5/202517/6/2026
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this…
AnalizadaAlta (7.1)0.41%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express21/5/202517/6/2026
A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An…
AplazadaMedia (4.8)0.31%—Intelbras RF 301kAI20/5/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…
AplazadaMedia (5.4)0.16%—Intel GaudiAI14/5/202517/6/2026
Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.8)0.18%—Intel Core UltraAI13/5/202517/6/2026
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.