Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.45% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This bypasses the read-only restriction… | |
| Analizada | Alta (8.6) | 0.58% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's readOnlyMasterKey option allows access with master-level read privileges but is documented to deny all write operations. However, some endpoints incorrectly… | |
| Modificada | Alta (7.5) | 0.25% | — | Ibexa EZ Platform | 6/3/2026 | 5/7/2026 | Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs. | |
| Modificada | Alta (8.1) | 0.49% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/3/2026 | 14/9/2026 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative… | |
| Analizada | Alta (7.5) | 0.76% | 💥 PoC | TCS Cognix Platform | 5/3/2026 | 17/6/2026 | Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network. | |
| Analizada | Alta (8.1) | 0.40% | 💥 PoC | TCS Cognix Platform | 5/3/2026 | 17/6/2026 | A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests. | |
| Analizada | Alta (8.8) | 0.59% | 💥 PoC | TCS Cognix Platform | 5/3/2026 | 17/6/2026 | An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role boundaries via crafted requests. | |
| Modificada | Media (6.5) | 0.47% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxLinux-nfs Nfs-utils | 4/3/2026 | 1/9/2026 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory,… | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Xg101039 FirmwareQualcomm Xg101032 Firmware+25 | 2/3/2026 | 17/6/2026 | Memory Corruption when processing invalid user address with nonstandard buffer address. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+160 | 2/3/2026 | 17/6/2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+90 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Alta (7.1) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+70 | 2/3/2026 | 17/6/2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+118 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p FirmwareQualcomm Sa7775p Firmware+165 | 2/3/2026 | 17/6/2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+184 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Analizada | Alta (8.6) | 0.59% | — | Intra-mart Accel Platform | 27/2/2026 | 17/6/2026 | IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted file is imported by a user with the administrative privilege. | |
| Analizada | Media (6.7) | 0.17% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to… | |
| Analizada | Media (6.7) | 0.20% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By… |