Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | Furbo Mini FirmwareFurbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A flaw has been found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Bluetooth Handler. Executing manipulation can lead to denial of service. The attacker needs to be present on the local network. The firmware versions determined to be affected are Furbo 360 up to… | |
| Analizada | Media (5.3) | 0.30% | — | Furbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component Audio Handler. Performing manipulation results in race condition. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any… | |
| Analizada | Media (6.3) | 0.40% | — | Furbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Account Handler. Such manipulation leads to server-side request forgery. The attack can be executed remotely. This attack is characterized by high complexity. The… | |
| Analizada | Media (5.3) | 0.45% | — | Furbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This manipulation causes resource consumption. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any… | |
| Analizada | Baja (2.4) | 0.19% | — | Furbo Mini FirmwareFurbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component UART Interface. The manipulation results in information disclosure. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited. The firmware… | |
| Analizada | Media (6.3) | 0.26% | — | Furbo Mini FirmwareFurbo 360 DOG Camera Firmware | 12/10/2025 | 17/6/2026 | A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs.sh of the component HTTP Traffic Handler. The manipulation leads to improper certificate validation. The attack may be initiated remotely. The attack is considered to… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 17/6/2026 | Memory corruption while processing a malformed license file during reboot. | |
| Aplazada | Baja (2) | 0.25% | — | Vanderlande Baggage 360AI | 5/10/2025 | 17/6/2026 | A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file /api-addons/v1/messages. Such manipulation of the argument Message leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The… | |
| Analizada | Media (4.9) | 0.31% | — | Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+108 | 25/9/2025 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+199 | 24/9/2025 | 17/6/2026 | Transient DOS while parsing the EPTM test control message to get the test pattern. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6174a FirmwareQualcomm Qca6391 Firmware+109 | 24/9/2025 | 17/6/2026 | Memory corruption while selecting the PLMN from SOR failed list. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+245 | 24/9/2025 | 17/6/2026 | Memory corruption while performing private key encryption in trusted application. | |
| Analizada | Alta (7.1) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+283 | 24/9/2025 | 25/9/2026 | Cryptographic issue while performing RSA PKCS padding decoding. | |
| Analizada | Media (6.8) | 0.29% | — | Positron Px360bt Firmware | 15/9/2025 | 17/6/2026 | The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including… | |
| Modificada | Alta (8.7) | 8.1% | — | Nsfocusglobal Secgate3600 Firmware | 27/8/2025 | 17/6/2026 | SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An unauthenticated remote attacker can… | |
| Aplazada | Media (6.4) | 0.25% | — | Ogulo 360 TourAI | 23/8/2025 | 17/6/2026 | The Ogulo – 360° Tour plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions up to, and including, 1.0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+368 | 6/8/2025 | 17/6/2026 | Transient DOS while processing an ANQP message. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8064au FirmwareQualcomm Ar8035 FirmwareQualcomm C-v2x 9150 Firmware+149 | 6/8/2025 | 17/6/2026 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+85 | 6/8/2025 | 17/6/2026 | Transient DOS while processing CCCH data when NW sends data with invalid length. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+345 | 6/8/2025 | 17/6/2026 | Information disclosure while processing the hash segment in an MBN file. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+338 | 6/8/2025 | 17/6/2026 | Information disclosure while reading data from an image using specified offset and size parameters. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+76 | 6/8/2025 | 17/6/2026 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. | |
| Aplazada | Media (6.4) | 0.19% | — | 360 Photo SpheresAI | 2/8/2025 | 17/6/2026 | The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.6) | 1.4% | 💥 Exploit | X360 VideoplayerAI | 16/7/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handling overly long arguments to the ConvertFile() method. An attacker can exploit this vulnerability by supplying crafted input to cause memory corruption and execute arbitrary code within the context of… | |
| Aplazada | Alta (8.9) | 0.83% | — | Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+2 | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The manipulation leads to improper authentication.… |