Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1654 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 30/7/2025 | 17/6/2026 | An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Modificada | Alta (8.8) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (8.8) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (7.5) | 1.2% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to cause unexpected system termination. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Aplazada | Alta (8.6) | 1.8% | 💥 Exploit | Lantronix Provisioning ManagerAI | 22/7/2025 | 17/6/2026 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. | |
| Aplazada | Media (6.8) | 0.28% | — | Okta On-premises ProvisioningAI | 22/7/2025 | 17/6/2026 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by… | |
| Aplazada | Alta (8.3) | 0.36% | — | Scati Labs Scati Vision WEBAI | 16/7/2025 | 17/6/2026 | SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the ‘login’ parameter in the endpoint ‘/scatevision_web/index.php/loginForm’. | |
| Analizada | Alta (8.8) | 9.5% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxApple SafariApple Ipados+6 | 15/7/2025 | 1/10/2026 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (7.2) | 71% | 💥 Exploit | SqliteApple IpadosApple Iphone OSApple Macos+5 | 15/7/2025 | 26/6/2026 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | |
| Aplazada | Baja (0.3) | 0.10% | — | Fnkvision Fnk-gu2AI | 9/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on the physical… | |
| Aplazada | Baja (0.3) | 0.10% | — | Fnkvision Fnk-gu2AI | 9/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow of the component MD5. The manipulation leads to risky cryptographic algorithm. It is possible to launch the attack on the physical device. The… | |
| Aplazada | Media (4.5) | 0.18% | — | Fnkvision Fnk-gu2AI | 9/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack on the physical device. The complexity… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | |
| Analizada | Alta (7.5) | 0.23% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+207 | 8/7/2025 | 17/6/2026 | Transient DOS while handling beacon frames with invalid IE header length. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+152 | 8/7/2025 | 17/6/2026 | Memory corruption while processing data packets in diag received from Unix clients. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption while processing video packets received from video firmware. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sa8620p FirmwareQualcomm Sa8650p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa8775p Firmware+188 | 8/7/2025 | 17/6/2026 | Transient DOS while processing received beacon frame. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+181 | 8/7/2025 | 17/6/2026 | Transient DOS may occur while processing malformed length field in SSID IEs. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+271 | 8/7/2025 | 17/6/2026 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | |
| Analizada | Alta (8.2) | 0.22% | — | Qualcomm Sm6250 FirmwareQualcomm Sm6370 FirmwareQualcomm Sm7315 FirmwareQualcomm Sm7325p Firmware+175 | 8/7/2025 | 17/6/2026 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+217 | 8/7/2025 | 17/6/2026 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+185 | 8/7/2025 | 17/6/2026 | Memory corruption while operating the mailbox in Automotive. | |
| Aplazada | Crítica (10) | 22% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Aplazada | Alta (8.7) | 0.85% | — | Hikvision Streaming Media Management ServerAI | 1/7/2025 | 17/6/2026 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory… |