Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
1722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+202 | 5/9/2023 | 17/6/2026 | Corrupción de memoria en WLAN al enviar comandos de transmisión desde HLOS a controladores UTF. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+126 | 5/9/2023 | 17/6/2026 | Corrupción de la memoria en el producto WIN al invocar el controlador de actualización WinAcpi en la región UEFI. | |
| Modificada | Media (6.1) | 0.56% | — | Foliovision FV Flowplayer Video Player | 25/8/2023 | 17/6/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212… | |
| Modificada | Media (6.1) | 0.40% | — | Foliovision FV Flowplayer Video Player | 18/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Server Debug AND Provisioning Tool | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 0.73% | — | Geovision Gv-adr2701 Firmware | 19/7/2023 | 17/6/2026 | In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. | |
| Modificada | Alta (7.8) | 0.16% | — | HPE Intelligent Provisioning | 18/7/2023 | 17/6/2026 | The vulnerability could be locally exploited to allow escalation of privilege. | |
| Analizada | Crítica (9.8) | 0.92% | — | Unitronics Vision1210 Firmware | 13/7/2023 | 17/6/2026 | Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+184 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while fetching TX status information. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+201 | 4/7/2023 | 17/6/2026 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 4/7/2023 | 17/6/2026 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+93 | 4/7/2023 | 17/6/2026 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 Firmware+208 | 4/7/2023 | 17/6/2026 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | |
| Modificada | Media (4.3) | 10% | 💥 PoC | Hikvision Ds-k1t804af FirmwareHikvision Ds-k1t804amf FirmwareHikvision Ds-k1t341am FirmwareHikvision Ds-k1t341amf Firmware+33 | 15/6/2023 | 17/6/2026 | Algunos productos de control de acceso/intercomunicación tienen vulnerabilidades de modificación no autorizada de la configuración de red del dispositivo. Los atacantes pueden modificar la configuración de red del dispositivo enviando paquetes de datos específicos a la interfaz vulnerable dentro de la misma red local. | |
| Modificada | Alta (7.5) | 0.64% | — | Hikvision Ds-k1t320efwx FirmwareHikvision Ds-k1t320efx FirmwareHikvision Ds-k1t320ewx FirmwareHikvision Ds-k1t320ex Firmware+22 | 15/6/2023 | 17/6/2026 | Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by… | |
| Modificada | Alta (8.1) | 0.47% | — | Arista Cloudvision Portal | 13/6/2023 | 17/6/2026 | On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. |