Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
8603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Snowflake Terraform ProviderAI | 8/7/2026 | 9/7/2026 | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of… | |
| Aplazada | Media (6.5) | 0.38% | — | Nomysoft Informatics Education AND Consulting INC NomysemAI | 8/7/2026 | 8/7/2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Crítica (9.1) | 1.2% | — | Simple Coherent FormAI | 8/7/2026 | 8/7/2026 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily… | |
| Aplazada | Alta (8.2) | 0.34% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (5.4) | 0.23% | — | Armiya Information Technologies Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (6.1) | 0.25% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (6.1) | 0.25% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2. | |
| Analizada | Alta (8.8) | 0.11% | — | Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+124 | 6/7/2026 | 7/7/2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+75 | 6/7/2026 | 7/7/2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | |
| Analizada | Alta (7.1) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+49 | 6/7/2026 | 8/7/2026 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+43 | 6/7/2026 | 7/7/2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+105 | 6/7/2026 | 7/7/2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. | |
| Aplazada | Alta (7.7) | 0.44% | — | Hashicorp Terraform EnterpriseAI | 6/7/2026 | 7/7/2026 | HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then… | |
| Analizada | Alta (7.3) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Corrupción de memoria al procesar múltiples llamadas IOCTL con la misma entrada de descriptor de archivo de búfer. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Corrupción de memoria al procesar múltiples llamadas IOCTL con la misma entrada de descriptor de archivo de búfer debido al acceso a memoria ya liberada. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+56 | 6/7/2026 | 29/9/2026 | Corrupción de memoria cuando se invocan operaciones de control de entrada/salida de dispositivo para mapear y desmapear búferes de memoria persistente debido a una sincronización inadecuada. | |
| Aplazada | Alta (7.5) | 0.48% | — | Notifications FOR Forms AND Wordpress ActionsAI | 6/7/2026 | 6/7/2026 | El plugin de WordPress Notifications for Forms & WordPress Actions, en versiones anteriores a la 2.6, no valida los valores proporcionados por el usuario antes de utilizarlos para crear una ruta de inclusión de archivos del lado del servidor, lo que permite a los usuarios autenticados con acceso de nivel suscriptor o… | |
| Aplazada | Media (6.9) | 0.63% | — | FormbricksAI | 6/7/2026 | 7/7/2026 | A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts of the component Survey Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. Upgrading to version 5.1.0-rc.1 will… | |
| Aplazada | Media (5.3) | 0.33% | — | Softaculous FormlayerAI | 5/7/2026 | 7/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6. | |
| Aplazada | Media (5.5) | 0.41% | — | Hanwang E-face General Management PlatformAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might… | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | Dell Client Platform BiosAI | 3/7/2026 | 7/7/2026 | Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Aplazada | Alta (7.2) | 0.53% | — | NEX FormsAI | 3/7/2026 | 7/7/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… |