Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.17% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+246 | 2/9/2024 | 17/6/2026 | Memory corruption when two threads try to map and unmap a single node simultaneously. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Memory corruption when user provides data for FM HCI command control operations. | |
| Analizada | Alta (7.5) | 0.30% | — | Qualcomm Ar8035 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+253 | 2/9/2024 | 17/6/2026 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+176 | 2/9/2024 | 17/6/2026 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+199 | 2/9/2024 | 17/6/2026 | Memory corruption when Alternative Frequency offset value is set to 255. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm4490 Firmware+41 | 2/9/2024 | 17/6/2026 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | |
| Analizada | Alta (8.4) | 0.13% | — | Qualcomm Qam8255p FirmwareQualcomm Qam8620p FirmwareQualcomm Qam8650p FirmwareQualcomm Qam8775p Firmware+86 | 2/9/2024 | 17/6/2026 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | |
| Analizada | Media (6.8) | 0.15% | — | Qualcomm Qcn9000 FirmwareQualcomm Qcn9011 FirmwareQualcomm Qcn9012 FirmwareQualcomm Qcn9013 Firmware+329 | 2/9/2024 | 17/6/2026 | memory corruption when an invalid firehose patch command is invoked. | |
| Analizada | Alta (7.1) | 0.12% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+228 | 2/9/2024 | 17/6/2026 | Cryptographic issue while parsing RSA keys in COBR format. | |
| Analizada | Alta (8.1) | 2.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/8/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Analizada | Alta (7.5) | 0.39% | — | Storelocatorplus Store Locator Plus | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01. | |
| Analizada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 23/8/2024 | 17/6/2026 | An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800. | |
| Modificada | Media (5.4) | 1.1% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25. | |
| Analizada | Alta (8.8) | 5.2% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. | |
| Analizada | Alta (8.8) | 4.0% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report. | |
| Analizada | Alta (8.8) | 7.0% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option. | |
| Analizada | Alta (8.8) | 5.3% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module. | |
| Analizada | Alta (8.8) | 4.4% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.0% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. | |
| Analizada | Media (5.4) | 0.26% | — | Posimyth THE Plus Addons FOR Elementor | 22/8/2024 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and… |