Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1857/4/202517/6/2026
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
AnalizadaAlta (7.5)0.30%💥 PoCQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc2073 FirmwareQualcomm Qcc2076 Firmware+2083/3/202517/6/2026
Transient DOS may occur while processing the country IE.
AnalizadaAlta (7.8)0.12%—Qualcomm Qcs6490 FirmwareQualcomm Qcs7230 FirmwareQualcomm Qcs8250 FirmwareQualcomm Qcs8300 Firmware+1623/3/202517/6/2026
Memory corruption in display driver while detaching a device.
AnalizadaCrítica (9.8)0.29%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1823/2/202517/6/2026
Memory corruption during management frame processing due to mismatch in T2LM info element.
AnalizadaAlta (7.5)0.31%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1653/2/202517/6/2026
Information disclosure while parsing the OCI IE with invalid length.
AnalizadaAlta (7.8)0.11%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1233/2/202517/6/2026
Memory corruption while power-up or power-down sequence of the camera sensor.
AnalizadaAlta (7.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1463/2/202517/6/2026
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
AnalizadaCrítica (9.8)0.58%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1703/2/202517/6/2026
Memory corruption while parsing the ML IE due to invalid frame content.
AnalizadaCrítica (9.8)3.7%—Dlink Di-8300 Firmware9/9/202417/6/2026
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
AnalizadaCrítica (9.8)3.2%—Dlink Di-8300 Firmware9/9/202417/6/2026
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
ModificadaAlta (8.1)100%💥 ExploitSonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+491/7/20241/9/2026
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
AnalizadaMedia (6.5)0.33%—Netgear Xr1000 FirmwareNetgear Xr300 FirmwareNetgear D6220 FirmwareNetgear D6400 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (8.8)0.58%—Netgear Dc112a FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
AnalizadaMedia (5.5)0.27%—Linux KernelDebian LinuxNetapp 8300 FirmwareNetapp 8700 Firmware+63/4/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must be registered before registering the generic netlink family.
AnalizadaMedia (5.5)0.26%—Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+253/4/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is…
ModificadaAlta (8)0.40%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaBaja (3.5)0.30%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (5.3)2.7%💥 PoCH3C Gr-1100-p FirmwareH3C Gr-1108-p FirmwareH3C Gr-1200w FirmwareH3C Gr-1800ax Firmware+1124/9/202317/6/2026
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config…
ModificadaAlta (8)0.35%—Intel Celeron J6413 FirmwareIntel Celeron N6211 FirmwareIntel Pentium J6425 FirmwareIntel Pentium N6415 Firmware+29411/8/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
ModificadaMedia (4.4)0.17%—Intel Pentium J6426 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+90211/8/202317/6/2026
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.5)3.0%—Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+53011/8/202317/6/2026
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.18%—Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+46310/5/202317/6/2026
Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.25%—Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+26910/5/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7)0.28%—Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+827/3/202317/6/2026
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing…
ModificadaMedia (6.5)0.42%—Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+33811/11/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.
Orbitaley — Vulnerabilidades