Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.17% | — | Hihonor Fri-an00 Firmware | 29/12/2023 | 17/6/2026 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure. | |
| Modificada | Crítica (9.8) | 0.56% | — | Hihonor Nth-an00 Firmware | 29/12/2023 | 17/6/2026 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | |
| Analizada | Alta (7.1) | 0.11% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | |
| Analizada | Alta (7.1) | 0.11% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | |
| Modificada | Media (5.5) | 0.17% | — | Hihonor Honorboardapp | 29/12/2023 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Modificada | Alta (7.1) | 0.11% | — | Hihonor Nth-an00 Firmware | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | |
| Modificada | Alta (7.1) | 0.11% | — | Hihonor Nth-an00 Firmware | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | |
| Modificada | Alta (7.1) | 0.12% | — | Hihonor Nth-an00 Firmware | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | |
| Modificada | Media (4.3) | 0.64% | — | Hono | 14/12/2023 | 17/6/2026 | Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values from previous requests if the application is using TrieRouter. So, there is a risk that a privileged user may use unintended parameters when deleting REST API resources. TrieRouter is used either… | |
| Modificada | Media (6.5) | 1.0% | — | TAD Honor Project TAD Honor | 8/10/2021 | 17/6/2026 | Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in. | |
| Modificada | Alta (8.8) | 1.1% | — | Eclipse Hono | 14/1/2021 | 17/6/2026 | The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission… | |
| Modificada | Alta (7.5) | 0.89% | — | Huawei Honor 20 PRO FirmwareHuawei Princeton-al10d FirmwareHuawei Yale-l21a FirmwareHuawei Yale-l61a Firmware | 29/12/2020 | 17/6/2026 | There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnormal messages, remote attackers may exploit this vulnerability to cause a denial of service (DoS) on the specific module. | |
| Modificada | Alta (7.8) | 0.83% | — | Huawei Honor 20 PRO FirmwareHuawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X Firmware+9 | 7/12/2020 | 17/6/2026 | There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege,… | |
| Modificada | Alta (7.5) | 1.3% | — | Eclipse Hono | 13/11/2020 | 17/6/2026 | In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link establishment. While the AMQP 1.0 protocol… | |
| Modificada | Media (5.5) | 0.24% | — | Huawei Honor 20 PRO FirmwareHuawei Honor View 20 FirmwareHuawei Oxfords-an00a FirmwareHuawei Princeton-al10b Firmware+6 | 3/9/2020 | 17/6/2026 | Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier… | |
| Modificada | Media (6.8) | 0.23% | — | Huawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X FirmwareHuawei P30 Firmware+6 | 11/8/2020 | 17/6/2026 | HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30… | |
| Modificada | Media (6.5) | 0.79% | — | Huawei Honor V30 Firmware | 17/7/2020 | 17/6/2026 | Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not sufficiently validate certain parameter passed from the bottom level, the attacker should trick the user into installing a malicious application and control the bottom… | |
| Modificada | Media (5.5) | 0.47% | — | Huawei Honor 10 Firmware | 17/7/2020 | 17/6/2026 | Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. Certain service in the system does not sufficiently validate certain parameter which is received, the attacker should trick the user into installing a malicious application, successful exploit could… | |
| Modificada | Media (4.6) | 0.21% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Anne-al00 Firmware+24 | 8/6/2020 | 17/6/2026 | Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in… | |
| Modificada | Media (5.3) | 0.73% | — | Huawei Honor 20 PRO FirmwareHuawei Honor View 20 FirmwareHuawei Honor 20 Firmware | 5/6/2020 | 17/6/2026 | Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability. A component cannot deal with an exception correctly. Attackers can exploit this vulnerability by sending malformed message. This could compromise normal service of affected phones. | |
| Modificada | Baja (2.4) | 0.25% | — | Huawei Honor 9X Firmware | 29/5/2020 | 17/6/2026 | Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unlocked, successful exploit could allow the attacker to access clock… | |
| Modificada | Media (6.5) | 0.34% | — | Huawei Anne-al00 FirmwareHuawei Berkeley-l09 FirmwareHuawei Cd16-10 FirmwareHuawei Cd17-10 Firmware+14 | 21/5/2020 | 17/6/2026 | There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly. Affected product versions include: Anne-AL00 Versions earlier than 9.1.0.331(C675E9R1P3T8); Berkeley-L09… | |
| Modificada | Alta (7.1) | 0.54% | — | Huawei Honor View 20 FirmwareHuawei Honor 20 FirmwareHuawei Honor 20 PRO FirmwareHuawei Honor Magic2 Firmware | 15/5/2020 | 17/6/2026 | Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.176(C00E60R2P11);9.1.0.135(C00E133R2P1); versions earlier than 10.1.0.123(C431E22R3P5),… | |
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2… | |
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1… |