Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.12% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+228 | 2/9/2024 | 17/6/2026 | Cryptographic issue while parsing RSA keys in COBR format. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Qcn9024 FirmwareQualcomm Qcs4490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 Firmware+157 | 2/9/2024 | 17/6/2026 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 7800 Firmware+49 | 2/9/2024 | 17/6/2026 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. | |
| Analizada | Crítica (9.8) | 0.96% | — | Opensecurity Mobile Security Framework | 19/8/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent… | |
| Modificada | Alta (7.5) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources. | |
| Modificada | Alta (8.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | |
| Analizada | Media (6.5) | 0.94% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information | |
| Modificada | Media (6.1) | 0.25% | — | Mozilla Firefox Mobile | 6/8/2024 | 19/8/2026 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. | |
| Modificada | Media (6.1) | 0.25% | — | Mozilla Firefox Mobile | 6/8/2024 | 19/8/2026 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. | |
| Analizada | Media (6.1) | 0.27% | — | Mozilla Firefox Mobile | 6/8/2024 | 19/8/2026 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129. | |
| Modificada | Alta (8.1) | 0.27% | — | Mozilla Firefox Mobile | 6/8/2024 | 19/8/2026 | A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+101 | 5/8/2024 | 17/6/2026 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+134 | 5/8/2024 | 17/6/2026 | Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm C-v2x 9150 Firmware+86 | 5/8/2024 | 17/6/2026 | Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+161 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+165 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+177 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+153 | 5/8/2024 | 17/6/2026 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+120 | 5/8/2024 | 17/6/2026 | Memory corruption while allocating memory in HGSL driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+134 | 5/8/2024 | 17/6/2026 | Memory corruption while processing IOCTL call to set metainfo. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+94 | 5/8/2024 | 17/6/2026 | Transient DOS while processing TID-to-link mapping IE elements. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+145 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the received TID-to-link mapping action frame. | |
| Analizada | Alta (7.5) | 0.33% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+147 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+191 | 5/8/2024 | 17/6/2026 | Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |