Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1064 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 2.3% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed. | |
| Aplazada | Media (6.9) | 0.12% | — | Elecom Wireless LAN Access PointAI | 13/5/2026 | 17/6/2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 7/10/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Alta (8.8) | 0.28% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 7/10/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Pendiente de análisis | Alta (7.3) | 0.38% | — | VenuelessAI | 5/4/2026 | 20/7/2026 | A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds. | |
| Pendiente de análisis | Alta (7.3) | 0.38% | — | VenuelessAI | 27/3/2026 | 17/6/2026 | A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on the same server due to a bug in the reporting feature. The exploitability is limited by the fact that the attacker needs to know the internal channel UUID of the chat… | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Cisco IOS XE Wireless Controller SoftwareAI | 25/3/2026 | 17/6/2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Aplazada | Baja (2.1) | 0.36% | — | Codegenieapp Serverless-expressAI | 16/3/2026 | 17/6/2026 | A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass.… | |
| Aplazada | Baja (2.1) | 0.39% | — | Codegenieapp Serverless-expressAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The attack may be initiated remotely. The exploit has been made available to the public… | |
| Analizada | Media (6.5) | 0.17% | — | Lesspass | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackers to obtain sensitive information. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Analizada | Media (5.3) | 0.25% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted filesystem path via the JSON key… | |
| Analizada | Media (5.3) | 0.19% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$Pv3$txtDescription parameter to /MailEssentials/pages/MailSecurity/general.aspx, which is stored and… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvSubject$TXB_SubjectCondition parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvGeneral$TXB_Condition parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$AntiSpoofingGeneral1$TxtSmtpDesc parameter to /MailEssentials/pages/MailSecurity/AntiSpoofing.aspx,… | |
| Analizada | Media (5.1) | 0.17% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv2$txtIPDescription parameter to… |