Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.19%—Apple IpadosApple Iphone OSApple MacosApple Visionos4/11/202525/9/2026
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.
ModificadaAlta (7.8)0.22%—Apple IpadosApple Iphone OSApple TvosApple Visionos4/11/202525/9/2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
ModificadaMedia (4.3)1.0%—Apple IpadosApple Iphone OSApple MacosApple Tvos+14/11/202525/9/2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt…
ModificadaMedia (4.3)1.0%—Apple IpadosApple Iphone OSApple MacosApple Tvos+14/11/202525/9/2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt…
ModificadaMedia (4.3)1.0%—Apple IpadosApple Iphone OSApple MacosApple Tvos+14/11/202525/9/2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt…
AplazadaAlta (7.5)0.35%—CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI24/10/202517/6/2026
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before…
AplazadaCrítica (9.3)0.49%—Cozyvision SMS Alert Order NotificationsAI22/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.
AnalizadaAlta (7)0.25%—Ghostrobotics Vision 60 Firmware22/10/202517/6/2026
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via SSH and gain full control of the robot,…
AnalizadaAlta (8.7)0.63%—Ghostrobotics Vision 60 Firmware22/10/202517/6/2026
Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router…
AnalizadaCrítica (9.2)0.31%—Ghostrobotics Vision 60 Firmware22/10/202517/6/2026
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of encryption and authentication mechanisms in the…
AplazadaAlta (8.3)1.3%—Hikvision CsmpAIHikvision Isecure CenterAI22/10/202517/6/2026
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.
AplazadaAlta (8.3)19%—Hikvision CsmpAIHikvision Isecure CenterAI22/10/20251/10/2026
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.
AplazadaCrítica (10)1.3%—Geovision Gv-bx1500AIGeovision Gv-mfd1501AI20/10/202517/6/2026
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this…
AplazadaCrítica (9.8)1.4%—Hikvision Isecure CenterAI17/10/202517/6/2026
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with…
AplazadaCrítica (9.8)0.50%—Hikvision Isecure CenterAI17/10/202517/6/2026
Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market only, with no overseas release.
ModificadaMedia (5.5)0.16%—Apple IpadosApple Iphone OSApple MacosApple Tvos+215/10/202517/6/2026
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to cause unexpected system termination.
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+3159/10/202517/6/2026
Memory corruption during PlayReady APP usecase while processing TA commands.
AplazadaCrítica (9.8)0.35%—Callvision Healthcare Callvision Emergency CodeAI7/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0.
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AplazadaAlta (8.7)0.26%—Keysight Ixia VisionAI30/9/202517/6/2026
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1,…
ModificadaMedia (5.3)0.26%💥 PoCTrivisionsecurity Trivision Nc-227wf Firmware29/9/202517/6/2026
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
ModificadaMedia (6.3)6.4%💥 PoCApple IpadosApple Iphone OSApple MacosApple Visionos29/9/202517/6/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to…
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+18824/9/202517/6/2026
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
AnalizadaCrítica (9.8)0.40%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+22324/9/202517/6/2026
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.