Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.1% | — | Motorola Sm56 Modem WDM DriverAI | 7/1/2025 | 17/6/2026 | A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed… | |
| Aplazada | Alta (8) | 0.94% | — | Motorola Cx2lAI | 8/10/2024 | 17/6/2026 | A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users… | |
| Analizada | Media (6.5) | 0.40% | — | Motorola Q14 Firmware | 31/7/2024 | 17/6/2026 | A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. | |
| Analizada | Alta (7.2) | 0.95% | — | Motorola Q14 Firmware | 31/7/2024 | 17/6/2026 | A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. | |
| Modificada | Media (5.3) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 2/7/2024 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary… | |
| Modificada | Alta (7.5) | 0.34% | — | Tvsmotor TVS Connect | 21/6/2024 | 17/6/2026 | TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access sensitive information via decryption. | |
| Modificada | Alta (8.6) | 0.39% | — | Motorola Vigilant Fixed LPR Coms BOX Firmware | 13/6/2024 | 17/6/2026 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. | |
| Modificada | Alta (7) | 0.15% | — | Motorola Vigilant Fixed LPR Coms BOX Firmware | 13/6/2024 | 17/6/2026 | An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text. | |
| Modificada | Media (5.1) | 0.25% | — | Motorola Vigilant Fixed LPR Coms BOX Firmware | 13/6/2024 | 17/6/2026 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. | |
| Aplazada | Baja (2.8) | 0.15% | — | Motorola FrameworkAI | 3/5/2024 | 17/6/2026 | An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. | |
| Aplazada | Baja (2.8) | 0.14% | — | Motorola Enterprise Motodpms ProviderAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data. | |
| Aplazada | Media (6.3) | 0.28% | — | Motorola GuidemeAI | 3/5/2024 | 17/6/2026 | A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files. | |
| Aplazada | Media (5.5) | 0.15% | — | Motorola Time Weather WidgetAI | 3/5/2024 | 17/6/2026 | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. | |
| Aplazada | Media (6.5) | 0.20% | — | Motorola Ready FORAI | 3/5/2024 | 17/6/2026 | An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. | |
| Aplazada | Media (4.4) | 0.16% | — | Motorola PhoneAI | 3/5/2024 | 17/6/2026 | An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider. | |
| Aplazada | Media (5.1) | 0.15% | — | Motorola Device HelpAI | 3/5/2024 | 17/6/2026 | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. | |
| Aplazada | Baja (2.8) | 0.18% | — | Motorola Ready FORAI | 3/5/2024 | 17/6/2026 | A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. | |
| Aplazada | Baja (2.8) | 0.14% | — | Motorola Phone CallsAI | 3/5/2024 | 17/6/2026 | An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data. | |
| Aplazada | Media (4.4) | 0.16% | — | Motorola Phone ExtensionAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. | |
| Aplazada | Media (4.8) | 0.14% | — | Motorola Interface Test ToolAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. | |
| Aplazada | Media (5) | 0.15% | — | Motorola SetupAI | 3/5/2024 | 17/6/2026 | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. | |
| Aplazada | Media (5) | 0.15% | — | Motorola Ready FORAI | 3/5/2024 | 17/6/2026 | An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. | |
| Aplazada | Media (6.1) | 0.14% | — | Motorola Face UnlockAI | 3/5/2024 | 17/6/2026 | A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. | |
| Aplazada | Media (5) | 0.15% | — | Motorola Device HelpAI | 3/5/2024 | 17/6/2026 | An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. | |
| Aplazada | Baja (2.8) | 0.14% | — | Motorola Phone CallsAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information. |