Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+23 | 9/10/2025 | 17/6/2026 | Memory corruption while invoking remote procedure IOCTL calls. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 FirmwareQualcomm Sc8380xp Firmware+14 | 9/10/2025 | 17/6/2026 | Memory corruption while processing an escape call. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 17/6/2026 | memory corruption while processing an image encoding completion event. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 FirmwareQualcomm Sc8380xp Firmware+14 | 9/10/2025 | 17/6/2026 | Memory corruption while processing IOCTL call to get the mapping. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 FirmwareQualcomm Sc8380xp Firmware+14 | 9/10/2025 | 17/6/2026 | Memory corruption while processing escape commands from userspace. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 17/6/2026 | Memory corruption while processing a malformed license file during reboot. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 17/6/2026 | Transient DOS while processing IOCTL call for image encoding. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Xg101039 FirmwareQualcomm Xg101032 FirmwareQualcomm Xg101002 FirmwareQualcomm X2000094 Firmware+14 | 9/10/2025 | 17/6/2026 | Memory corruption while processing camera platform driver IOCTL calls. | |
| Analizada | Media (6.1) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 FirmwareQualcomm Sc8380xp Firmware+14 | 9/10/2025 | 17/6/2026 | Information disclosure while processing batch command execution in Video driver. | |
| Analizada | Alta (8) | 0.61% | — | Totolink X2000r Firmware | 12/9/2025 | 17/6/2026 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password | |
| Analizada | Baja (1.1) | 0.21% | — | Totolink X2000r Firmware | 28/8/2025 | 25/7/2026 | A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly… | |
| Analizada | Alta (8.6) | 0.95% | — | Totolink N600r FirmwareTotolink X2000r Firmware | 26/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely. | |
| Analizada | Media (4.8) | 0.33% | — | Totolink X2000r Firmware | 3/6/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (4.8) | 0.33% | — | Totolink X2000r Firmware | 3/6/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. It is possible to launch the attack… | |
| Analizada | Media (4.8) | 0.36% | — | Totolink X2000r Firmware | 3/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Media (5.3) | 3.2% | — | Totolink X2000r Firmware | 3/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel. The manipulation of the argument devicemac1 leads to command injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 13% | — | Totolink X2000r Firmware | 3/6/2025 | 17/6/2026 | A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the argument peerRptPin leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Yokogawa Gx10AIYokogawa Gx20AIYokogawa Gp10AIYokogawa Gp20AI+12 | 18/4/2025 | 17/6/2026 | Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all functions related to settings and… | |
| Analizada | Media (4.8) | 0.63% | — | Totolink X2000r Firmware | 14/5/2024 | 17/6/2026 | Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page. | |
| Analizada | Media (5.9) | 0.43% | — | Totolink X2000r Firmware | 11/4/2024 | 17/6/2026 | TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page. | |
| Modificada | Media (5.4) | 0.39% | — | Totolink X2000r Firmware | 20/3/2024 | 17/6/2026 | There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013. | |
| Analizada | Alta (8) | 0.48% | — | Totolink X2000r Firmware | 15/3/2024 | 17/6/2026 | TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page. | |
| Modificada | Media (5.4) | 0.39% | — | Totolink X2000r Firmware | 15/3/2024 | 17/6/2026 | TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page. | |
| Modificada | Media (5.4) | 0.39% | — | Totolink X2000r Firmware | 15/3/2024 | 17/6/2026 | TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink X2000r Firmware | 25/1/2024 | 17/6/2026 | TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa. |