Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.14% | — | Watchguard Mobile VPN With SSLWatchguard Fireware | 3/7/2026 | 10/8/2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2. | |
| Analizada | Media (4.3) | 0.14% | — | Mozilla Firefox Mobile | 16/6/2026 | 17/6/2026 | Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0. | |
| Analizada | Media (6.5) | 0.14% | — | Mozilla Firefox Mobile | 16/6/2026 | 17/6/2026 | Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0. | |
| Aplazada | Alta (8.2) | 0.34% | — | Hippoo Mobile APP FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Crítica (9.8) | 1.6% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 11/6/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. | |
| Aplazada | Media (5.3) | 0.52% | — | MVT Mobile Verification ToolkitAI | 8/6/2026 | 23/7/2026 | MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to version 2026.5.12, there is a path traversal vulnerability via unsanitized File identifiers in iOS Backup processing. This issue has been patched in version 2026.5.12. | |
| Aplazada | Crítica (9.8) | 2.9% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 5/6/2026 | 17/6/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both… | |
| Aplazada | Alta (8.8) | 0.42% | — | Kurt Software Studio Writeup Mobile APPAI | 4/6/2026 | 22/7/2026 | Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026. | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to buffer overflow. | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to missing bounds check. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+38 | 1/6/2026 | 22/7/2026 | Memory corruption while processing multiple IOCTL command for escape operations. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+214 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing fastboot commands to set display mode. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.1) | 0.06% | — | Qualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 1 Mobile Platform FirmwareQualcomm Smart Audio 400 Platform Firmware+213 | 1/6/2026 | 22/7/2026 | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+215 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with invalid input. | |
| Analizada | Alta (8.2) | 0.07% | 💥 PoC | Qualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+242 | 1/6/2026 | 22/7/2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+211 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot OEM commands. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.7) | 0.08% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+40 | 1/6/2026 | 22/7/2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+183 | 1/6/2026 | 22/7/2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s FirmwareQualcomm Cq8750m Firmware+137 | 1/6/2026 | 22/7/2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+136 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon 480 5G Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 3 Mobile Platform Firmware+261 | 1/6/2026 | 22/7/2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | |
| Aplazada | Alta (8.8) | 0.43% | — | Frontier X Mobile ApplicationAISeil X2AI | 29/5/2026 | 22/7/2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,… |