Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.41%—Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+18113/4/202317/6/2026
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
ModificadaAlta (7.8)0.12%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+22113/4/202317/6/2026
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
ModificadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 Firmware+7313/4/202317/6/2026
Memory corruption due to use after free in Modem while modem initialization.
ModificadaMedia (5.5)0.11%—Qualcomm Qca6310 FirmwareQualcomm Qca6320 FirmwareQualcomm Sd835 FirmwareQualcomm Snapdragon 835 Mobile Platform Firmware+613/4/202317/6/2026
Information disclosure due to buffer overread in Linux sensors
ModificadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+11013/4/202317/6/2026
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
ModificadaMedia (6.8)0.19%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+22213/4/202317/6/2026
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
ModificadaAlta (7.8)0.08%—Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+21513/4/202317/6/2026
Memory corruption due to double free in core while initializing the encryption key.
ModificadaMedia (5.5)0.34%—Kyocera Mobile PrintTriumph-adler Mobile PrintOlivetti Mobile Print13/4/202317/6/2026
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may send an intent and direct the affected…
ModificadaAlta (7.8)0.51%—Chinamobileltd OA Mailbox PC10/4/202317/6/2026
An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.
ModificadaCrítica (9.8)0.74%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website6/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to…
ModificadaAlta (7.8)0.43%—Wondershare Mobiletrans4/4/202317/6/2026
An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.
ModificadaCrítica (9.8)0.73%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website2/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may…
ModificadaMedia (5.4)0.38%—Amauri Wpmobile.app23/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
ModificadaMedia (6.1)0.57%—Mobilevikings Django Ajax Utilities10/3/202317/6/2026
A vulnerability was found in Mobile Vikings Django AJAX Utilities up to 1.2.1 and classified as problematic. This issue affects the function Pagination of the file django_ajax/static/ajax-utilities/js/pagination.js of the component Backslash Handler. The manipulation of the argument url leads to cross site scripting.…
ModificadaCrítica (9.8)0.72%—Libimobiledevice Libplist21/2/202317/6/2026
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to…
ModificadaMedia (6.1)0.41%—Mozilla Firefox Mobile16/2/202319/8/2026
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
ModificadaCrítica (9.1)0.56%—Elwsc Kasago Ipv4Elwsc Kasago Ipv4 LightElwsc Kasago Ipv6/v4 DualElwsc Kasago Mobile Ipv610/2/202317/6/2026
La pila KASAGO TCP/IP proporcionada por Zuken Elmic genera ISN (número de secuencia inicial) para conexiones TCP desde una fuente insuficientemente aleatoria. Un atacante puede determinar el ISN de las conexiones TCP actuales o futuras y secuestrar las existentes o falsificar las futuras.
ModificadaMedia (6.1)2.7%💥 ExploitMobiledetect4/2/202317/6/2026
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated…
ModificadaAlta (7)0.14%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3131/2/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
ModificadaAlta (7.8)0.31%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3231/2/202317/6/2026
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.17%—HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+3731/2/202317/6/2026
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.
ModificadaCrítica (9.1)1.3%—Chinamobileltd Gpn2.4p21-c-cn Firmware26/1/202317/6/2026
Vulnerabilidad de Directory Traversal en el router inalámbrico ChinaMobile PLC modelo GPN2.4P21-C-CN que ejecuta la versión de firmware W2000EN-01 (plataforma de hardware Gpn2.4P21-C_WIFI-V0.05), a través del parámetro getpage en /cgi-bin/webproc.
ModificadaCrítica (9.1)1.0%—Chinamobileltd Gpn2.4p21-c-cn Firmware26/1/202317/6/2026
Se descubrió un problema en la configuración predeterminada del router inalámbrico ChinaMobile PLC modelo GPN2.4P21-C-CN que ejecuta la versión de firmware W2000EN-01 (plataforma de hardware Gpn2.4P21-C_WIFI-V0.05), que permite a los atacantes obtener acceso a la interfaz de configuración.
Orbitaley — Vulnerabilidades