Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcd9375 FirmwareQualcomm Wcd9378c FirmwareQualcomm Wcd9380 FirmwareQualcomm Wcd9385 Firmware+47 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sm6250 FirmwareQualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Snapdragon 7C Compute Platform Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Snapdragon 8CX Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware+48 | 6/4/2026 | 17/6/2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | |
| Analizada | Media (6.5) | 0.44% | — | Emqx Cocoamqtt | 2/4/2026 | 17/6/2026 | CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an attacker (or a compromised/malicious MQTT broker) to remotely crash the host iOS/macOS/tvOS application. If an attacker publishes the 4-byte… | |
| Aplazada | Alta (7.5) | 0.51% | — | Redqteam Turbo ManagerAIPHPAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8. | |
| Analizada | Baja (2) | 0.62% | — | Qnap QTSQnap Quts Hero | 11/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions:… | |
| Aplazada | Media (6.4) | 0.16% | — | MyqtipAI | 7/3/2026 | 17/6/2026 | The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Crítica (9.2) | 0.67% | — | Qnap QTSQnap Quts Hero | 11/2/2026 | 17/6/2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS… | |
| Analizada | Baja (1.2) | 0.53% | — | Qnap QTSQnap Quts Hero | 11/2/2026 | 17/6/2026 | A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the… | |
| Analizada | Baja (0.6) | 0.42% | — | Qnap QTSQnap Quts Hero | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build… | |
| Analizada | Media (5.1) | 0.44% | — | Qnap QTSQnap Quts Hero | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6420 FirmwareQualcomm Qca6430 FirmwareQualcomm Qcc2072 Firmware+33 | 2/2/2026 | 17/6/2026 | Memory Corruption when multiple threads simultaneously access a memory free API. | |
| Analizada | Alta (7.5) | 0.33% | — | Justdoit0910 Tinymqtt | 20/1/2026 | 17/6/2026 | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failure to validate or reject malformed UTF-8 strings in topic filters. An attacker can exploit this by sending repeated subscription requests with arbitrarily large or invalid filter payloads. Each… | |
| Aplazada | Crítica (9.3) | 0.43% | — | ProjeqtorAI | 15/1/2026 | 17/6/2026 | ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment section and execute system commands by accessing the uploaded file with a specially… | |
| Modificada | Alta (8.8) | 0.47% | — | Hikvision Ds-k1t331 FirmwareHikvision Ds-k1t341a FirmwareHikvision Ds-k1t341b FirmwareHikvision Ds-k1t671 Firmware+24 | 13/1/2026 | 9/7/2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. | |
| Aplazada | Alta (8.9) | 0.15% | — | MqttAI | 7/1/2026 | 17/6/2026 | An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+200 | 7/1/2026 | 7/10/2026 | Memory corruption while processing identity credential operations in the trusted application. | |
| Analizada | Media (6.6) | 0.08% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+235 | 7/1/2026 | 7/10/2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | |
| Analizada | Baja (2.7) | 0.45% | — | Qnap QTSQnap Quts Hero | 2/1/2026 | 17/6/2026 | An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following versions: QTS… | |
| Modificada | Media (6.9) | 0.47% | — | Qnap QTSQnap Quts Hero | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (4.6) | 0.58% | — | Qnap QTSQnap Quts Hero | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (1.2) | 0.36% | — | Qnap QTSQnap Quts Hero | 2/1/2026 | 7/10/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build… |