Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.17%—Cvat Computer Vision Annotation Tool21/1/202617/6/2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in a CVAT task or project, then get the…
AplazadaMedia (5.3)0.37%—Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI21/1/202617/6/2026
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by…
AnalizadaMedia (5.5)0.08%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1717/1/20267/10/2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+2007/1/20267/10/2026
Memory corruption while processing identity credential operations in the trusted application.
AnalizadaMedia (6.7)0.08%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1427/1/20267/10/2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
AnalizadaMedia (6.6)0.08%—Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+2357/1/20267/10/2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
AnalizadaMedia (6.1)0.08%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2957/1/20267/10/2026
Information disclosure while processing a firmware event.
AnalizadaMedia (5.5)0.07%—Qualcomm Qca6678aq FirmwareQualcomm Qca6688aq FirmwareQualcomm Qca6696 FirmwareQualcomm Qca6698aq Firmware+2197/1/20267/10/2026
Transient DOS while parsing video packets received from the video firmware.
AnalizadaMedia (5.3)0.29%—Cvat Computer Vision Annotation Tool19/12/202517/6/2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and…
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+4118/12/202517/6/2026
Memory Corruption when processing IOCTLs for JPEG data without verification.
AnalizadaAlta (7.8)0.08%—Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+20918/12/202517/6/2026
Memory corruption while processing MFC channel configuration during music playback.
AnalizadaAlta (7.8)0.10%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+10718/12/202517/6/2026
Memory corruption during video playback when video session open fails with time out error.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+17418/12/202530/9/2026
Memory corruption while routing GPR packets between user and root when handling large data packet.
AnalizadaMedia (5.5)0.39%—Carmelo Computer Book Store14/12/202517/6/2026
A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be…
AnalizadaBaja (2)0.39%—Carmelo Computer Laboratory System14/12/202517/6/2026
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2)0.39%—Carmelo Computer Laboratory System14/12/202517/6/2026
A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaAlta (7.6)0.24%—Aksis Computer Services AND Consulting INC AxonboardAI11/12/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers. This issue affects AxOnboard: from 3.2.0 before 3.3.0.
AplazadaCrítica (9.8)0.33%—Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI19/11/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119.
AnalizadaMedia (6.5)0.12%—Qualcomm Ar8035 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1324/11/202517/6/2026
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
AnalizadaAlta (7.8)0.09%—Qualcomm Qcm6490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 FirmwareQualcomm Video Collaboration VC3 Platform Firmware+274/11/202517/6/2026
Memory corruption while accessing a buffer during IOCTL processing.
AnalizadaAlta (7.8)0.06%—Qualcomm Qcs615 FirmwareQualcomm Qcs6490 FirmwareQualcomm Qcs8300 FirmwareQualcomm Qcs8550 Firmware+1714/11/202517/6/2026
Memory corruption while performing encryption and decryption commands.
AplazadaAlta (7.5)0.35%—CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI24/10/202517/6/2026
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before…
AnalizadaCrítica (9.8)0.77%—Microsoft Azure Compute Resource Provider23/10/202517/6/2026
Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.2)0.44%—Microsoft Azure Compute Gallery14/10/202517/6/2026
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.2)0.44%—Microsoft Azure Compute Gallery14/10/202517/6/2026
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
Orbitaley — Vulnerabilidades