Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 0.32% | — | Oretnom23 Computer AND Mobile Repair Shop Management System | 13/4/2026 | 17/6/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php. | |
| Pendiente de análisis | Crítica (9.3) | 0.10% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+3 | 8/4/2026 | 24/7/2026 | Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi… | |
| Pendiente de análisis | Crítica (9.3) | 0.10% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+3 | 8/4/2026 | 24/7/2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi… | |
| Analizada | Alta (8.8) | 0.45% | — | Mobilenexthq Mobile MCP | 6/4/2026 | 24/7/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and… | |
| Analizada | Alta (7.5) | 0.15% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+99 | 6/4/2026 | 17/6/2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcd9375 FirmwareQualcomm Wcd9378c FirmwareQualcomm Wcd9380 FirmwareQualcomm Wcd9385 Firmware+47 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcn3988 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8835 Firmware+31 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sm6250 FirmwareQualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Snapdragon 7C Compute Platform Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm X2000094 FirmwareQualcomm Xg101002 FirmwareQualcomm Xg101032 FirmwareQualcomm Xg101039 Firmware+24 | 6/4/2026 | 17/6/2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Snapdragon 8CX Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform FirmwareQualcomm Snapdragon 8CX GEN 2 5G Compute Platform "poipu Pro" FirmwareQualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware+48 | 6/4/2026 | 17/6/2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Analizada | Alta (8.8) | 0.28% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 7/10/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+97 | 6/4/2026 | 7/10/2026 | Memory corruption while processing a frame request from user. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+177 | 6/4/2026 | 7/10/2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | |
| Analizada | Media (6.1) | 0.34% | — | Streetwriters Notesnook Mobile | 1/4/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor… | |
| Modificada | Alta (8.4) | 0.21% | — | Triumph-adler Mobile Print | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Analizada | Media (6.5) | 0.52% | — | Mobilenexthq Mobile MCP | 27/3/2026 | 17/6/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directly to filesystem… | |
| Analizada | Crítica (9.6) | 0.69% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 27/3/2026 | 17/6/2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element… | |
| Analizada | Media (6.5) | 0.40% | — | Opensecurity Mobile Security Framework | 26/3/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Syarif Mobile APP EditorAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1. | |
| Analizada | Media (5.4) | 0.24% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 11/3/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an… | |
| Pendiente de análisis | Baja (2.4) | 0.15% | — | Heliox Flex 180 KW EV Charging StationAIHeliox Mobile DC 40 KW EV Charging StationAI | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lambertgroup Uberslider PerpetuummobileAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider PerpetuumMobile uberSlider_perpetuummobile allows Reflected XSS.This issue affects UberSlider PerpetuumMobile: from n/a through <= 2.3. |