Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
841 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.43% | — | Carmelo Computer Laboratory System | 10/10/2025 | 5/7/2026 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+23 | 9/10/2025 | 17/6/2026 | Memory corruption while invoking remote procedure IOCTL calls. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 17/6/2026 | memory corruption while processing an image encoding completion event. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 17/6/2026 | Memory corruption while processing a malformed license file during reboot. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+315 | 9/10/2025 | 17/6/2026 | Memory corruption during PlayReady APP usecase while processing TA commands. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 17/6/2026 | Transient DOS while processing IOCTL call for image encoding. | |
| Analizada | Media (5.5) | 0.50% | — | Campcodes Computer Sales AND Inventory System | 28/9/2025 | 30/9/2026 | A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and… | |
| Analizada | Media (5.5) | 0.44% | — | Campcodes Computer Sales AND Inventory System | 26/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_edit1.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.3) | 0.25% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections. | |
| Analizada | Alta (7.5) | 0.43% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions. | |
| Analizada | Media (5.4) | 0.23% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls. | |
| Aplazada | Alta (8.9) | 0.27% | — | Proliz Computer Software Hardware Service Trade LTD OBSAI | 25/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS. This issue affects OBS (Student Affairs Information System): before v25.0401. | |
| Aplazada | Alta (8.6) | 0.45% | — | Saysis Computer Systems Trade LTD CO Saysis WEB PortalAI | 25/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal. This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+37 | 24/9/2025 | 17/6/2026 | Memory corruption while encoding the image data. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+199 | 24/9/2025 | 17/6/2026 | Transient DOS while parsing the EPTM test control message to get the test pattern. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+25 | 24/9/2025 | 17/6/2026 | Memory corruption due to double free when multiple threads race to set the timestamp store. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6174a FirmwareQualcomm Qca6391 Firmware+109 | 24/9/2025 | 17/6/2026 | Memory corruption while selecting the PLMN from SOR failed list. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+188 | 24/9/2025 | 17/6/2026 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+245 | 24/9/2025 | 17/6/2026 | Memory corruption while performing private key encryption in trusted application. | |
| Analizada | Media (6.1) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+17 | 24/9/2025 | 25/9/2026 | Information disclosure when Video engine escape input data is less than expected minimum size. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | |
| Analizada | Alta (7.1) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+283 | 24/9/2025 | 25/9/2026 | Cryptographic issue while performing RSA PKCS padding decoding. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Computer Sales AND Inventory System | 23/9/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. The manipulation of the argument prodcode leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Computer Sales AND Inventory System | 23/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/inv_edit1.php. Executing manipulation of the argument idd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. |