Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
AplazadaAlta (8.8)0.47%—UltradagAI8/5/202617/6/2026
UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its policy enforcement pipeline. When a transaction originates from a "Pocket" (a derived sub-address documented in the protocol as a way to organize…
AnalizadaAlta (7.8)0.07%—Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+1724/5/202629/6/2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
AnalizadaAlta (7.8)0.07%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/20267/10/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AnalizadaAlta (7.5)0.22%—Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+2534/5/20267/10/2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
AnalizadaAlta (7.5)0.22%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2414/5/20267/10/2026
Transient DOS when processing target power rate tables during channel configuration.
AnalizadaMedia (6.9)0.18%—Ezbsystems Ultraiso22/4/202617/6/2026
UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into…
AnalizadaAlta (8.8)0.57%—Ultradag21/4/202617/6/2026
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.
AnalizadaAlta (7.5)0.15%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+996/4/202617/6/2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
AnalizadaAlta (7.5)0.20%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+1466/4/202617/6/2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
AnalizadaAlta (8.8)0.17%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/20267/10/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
AnalizadaAlta (7.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1776/4/20267/10/2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
AnalizadaMedia (6.4)0.19%—Uvnc Ultravnc27/3/202617/6/2026
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs to be approached locally. This attack is characterized by high complexity. The…
AnalizadaMedia (6.3)0.07%💥 PoCUltraviolet Cocos AI27/3/202617/6/2026
Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions from v0.4.0 through v0.8.2. This vulnerability is present in both the AMD SEV-SNP and Intel TDX deployment targets supported by CoCoS. In the affected…
AplazadaAlta (7.1)0.18%—Themepassion Ultra Wordpress AdminAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra WordPress Admin: from n/a through <= 11.7.
AplazadaMedia (6.9)0.26%—Ultravnc LauncherAI22/3/202617/6/2026
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of…
AplazadaAlta (7.1)0.69%—Ultravnc ViewerAI22/3/202617/6/2026
UltraVNC Viewer 1.2.2.4 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized string to the VNC Server input field. Attackers can paste a malicious string containing 256 repeated characters into the VNC Server field and click Connect to trigger a buffer…
ModificadaAlta (7.5)0.77%—Ultrajson Project Ultrajson20/3/202615/7/2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the product of the indent parameter and the…
ModificadaAlta (7.5)0.68%—Ultrajson Project Ultrajson20/3/202615/7/2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL…
AnalizadaMedia (6.4)0.18%—Uvnc Ultravnc8/3/202617/6/2026
A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is…
AplazadaAlta (7.1)0.26%—Lambertgroup Uberslider UltraAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Ultra uberSlider_ultra allows Reflected XSS.This issue affects UberSlider Ultra: from n/a through <= 2.3.
AnalizadaCrítica (9.6)0.48%—Pebblepower Pebble Prism Ultra Firmware4/3/202617/6/2026
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over…
AnalizadaAlta (7.8)0.07%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1662/3/202617/6/2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
AnalizadaAlta (7.2)0.14%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+2022/3/202617/6/2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
AnalizadaAlta (7.8)0.07%—Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+1742/3/202617/6/2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Orbitaley — Vulnerabilidades