Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.07%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1182/3/202617/6/2026
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
AnalizadaAlta (7.8)0.07%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1662/3/202617/6/2026
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
AnalizadaAlta (7.8)0.07%—Qualcomm Sa6150p FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p FirmwareQualcomm Sa7775p Firmware+1652/3/202617/6/2026
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
AnalizadaAlta (7.8)0.07%—Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+1842/3/202617/6/2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1212/3/202617/6/2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
AplazadaMedia (4.6)0.41%—Ultravnc ViewerAI5/2/202617/6/2026
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.
AnalizadaMedia (6.7)0.55%—Uvnc Ultravnc5/2/202617/6/2026
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.
AnalizadaMedia (6.7)0.26%—Uvnc Ultravnc5/2/202617/6/2026
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.
AnalizadaMedia (6.5)0.16%—Qualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p FirmwareQualcomm Sar2130p Firmware+902/2/202617/6/2026
Transient DOS when processing a received frame with an excessively large authentication information element.
AplazadaAlta (8.5)0.29%—Themepassion Ultra PortfolioAI22/1/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra Portfolio ultra-portfolio allows Blind SQL Injection.This issue affects Ultra Portfolio: from n/a through <= 6.7.
AplazadaMedia (6.5)0.41%—Deetronix Booking Ultra PROAI22/1/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23.
AnalizadaAlta (7.9)0.17%—ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+714/1/202617/6/2026
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
AplazadaMedia (4.3)0.35%—Ultra Addons FOR Contact Form 7AI12/12/202517/6/2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AplazadaMedia (6.4)0.23%—Ultra Skype ButtonAI6/12/202517/6/2026
The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of the [ultra_skype] shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.16%—Magewell Ultra Encode Hdmi FirmwareMagewell Ultra Encode SDI FirmwareMagewell Ultra Encode Hdmi Plus FirmwareMagewell Ultra Encode SDI Plus Firmware+124/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
AplazadaMedia (6.6)0.13%—AMD Zynq Ultrascale PlusAI6/10/202517/6/2026
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality.
AplazadaMedia (6.4)0.30%—Ultra Addons LiteAI3/10/202517/6/2026
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated Text' field of the Typeout Widget in version 1.1.9 and below due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (6.5)0.17%—Deetronix Booking Ultra PROAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.21.
AplazadaAlta (7.1)0.24%—Themepassion Ultra PortfolioAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra Portfolio ultra-portfolio allows Reflected XSS.This issue affects Ultra Portfolio: from n/a through <= 6.7.
AplazadaCrítica (9.3)0.10%—Themify UltraAI28/7/202517/6/2026
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
AplazadaCrítica (9.4)0.90%—Themify UltraAI28/7/202517/6/2026
OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.
AnalizadaAlta (7.5)0.48%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this…
AnalizadaAlta (8.8)0.39%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to…
AnalizadaMedia (6.8)0.34%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required…
AnalizadaMedia (6.8)0.34%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to exploit this…