Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.42%—Campcodes Computer Sales AND Inventory System23/9/202517/6/2026
A vulnerability was detected in Campcodes Computer Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/sup_edit1.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AplazadaMedia (6.5)0.40%—Proliz Computer Software Hardware Service Trade LTD CO OBSAI22/9/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Parameter Injection. This issue affects OBS (Student Affairs Information System): before v26.0328.
AplazadaMedia (6.3)0.25%—Saysis Computer Systems Trade Ltd. CO Starcities E-municipality ManagementAI19/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS). This issue affects StarCities E-Municipality Management: before 20250825.
AplazadaAlta (7.5)0.45%—Beyaz Computer CityplusAI19/9/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal. This issue affects CityPlus: before 24.29375.
ModificadaAlta (7.3)0.32%—Carmelo Computer Laboratory System16/9/20255/7/2026
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
AnalizadaMedia (6.1)0.28%—Askar634 Computer Base Test16/9/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php.
AnalizadaMedia (5.5)0.48%—Campcodes Computer Sales AND Inventory System15/9/202517/6/2026
A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_searchfrm.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (5.5)0.48%—Campcodes Computer Sales AND Inventory System15/9/202517/6/2026
A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/us_transac.php?action=add. Executing manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to…
AnalizadaMedia (5.5)0.43%—Campcodes Computer Sales AND Inventory System15/9/202517/6/2026
A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/sup_searchfrm.php?action=edit. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made…
AnalizadaMedia (5.5)0.42%—Campcodes Computer Sales AND Inventory System15/9/202517/6/2026
A security flaw has been discovered in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.42%—Campcodes Computer Sales AND Inventory System1/9/202517/6/2026
A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/pos_transac.php?action=add. Executing manipulation of the argument cash/firstname can lead to sql injection. The attack may be performed from remote. The exploit has been published…
AnalizadaAlta (7)0.07%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+416/8/202517/6/2026
Memory corruption while processing simultaneous requests via escape path.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+326/8/202517/6/2026
Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+126/8/202517/6/2026
Memory corruption while processing an IOCTL command with an arbitrary address.
AnalizadaAlta (7.5)0.28%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3686/8/202517/6/2026
Transient DOS while processing an ANQP message.
AnalizadaAlta (7.8)0.08%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8064au FirmwareQualcomm Ar8035 FirmwareQualcomm C-v2x 9150 Firmware+1496/8/202517/6/2026
Memory corruption while handling client exceptions, allowing unauthorized channel access.
AnalizadaAlta (7.5)0.21%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+856/8/202517/6/2026
Transient DOS while processing CCCH data when NW sends data with invalid length.
AnalizadaMedia (6.5)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+3456/8/202517/6/2026
Information disclosure while processing the hash segment in an MBN file.
AnalizadaMedia (6.5)0.09%—Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+3386/8/202517/6/2026
Information disclosure while reading data from an image using specified offset and size parameters.
AnalizadaAlta (7.5)0.21%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+766/8/202517/6/2026
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
AnalizadaMedia (6.5)0.27%—Cvat Computer Vision Annotation Tool30/7/202517/6/2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the product as verified users. Additionally,…
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+368/7/202517/6/2026
Memory corruption during the image encoding process.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+368/7/202517/6/2026
Memory corruption while processing event close when client process terminates abruptly.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+168/7/202517/6/2026
Memory corruption while processing the TESTPATTERNCONFIG escape path.