Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.14% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+309 | 5/12/2023 | 17/6/2026 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | |
| Modificada | Alta (8.8) | 0.14% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+277 | 5/12/2023 | 17/6/2026 | Memory corruption while loading an ELF segment in TEE Kernel. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+244 | 5/12/2023 | 17/6/2026 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+331 | 5/12/2023 | 17/6/2026 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+276 | 5/12/2023 | 17/6/2026 | Memory Corruption in SPS Application while exporting public key in sorter TA. | |
| Modificada | Media (5.4) | 0.46% | — | Cisco IP Dect 110 FirmwareCisco IP Dect 210 FirmwareCisco Unified IP Phone 6901 FirmwareCisco Unified SIP Phone 3905 Firmware | 21/11/2023 | 17/6/2026 | A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Alta (7.5) | 0.59% | — | Samsung Exynos 9810 FirmwareSamsung Exynos 9610 FirmwareSamsung Exynos 9820 FirmwareSamsung Exynos 980 Firmware+12 | 8/11/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of… | |
| Modificada | Alta (7.5) | 0.59% | — | Samsung Exynos 9810 FirmwareSamsung Exynos 9610 FirmwareSamsung Exynos 9820 FirmwareSamsung Exynos 980 Firmware+12 | 8/11/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). Improper handling of a length parameter inconsistency can cause abnormal termination of a… | |
| Modificada | Alta (7.8) | 0.13% | — | Qualcomm Ar8035 FirmwareQualcomm Wcn6750 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+74 | 7/11/2023 | 17/6/2026 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+222 | 7/11/2023 | 17/6/2026 | Cryptographic issue in HLOS during key management. | |
| Modificada | Alta (7.8) | 0.14% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+200 | 7/11/2023 | 17/6/2026 | Memory corruption in TZ Secure OS while loading an app ELF. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 7/11/2023 | 17/6/2026 | Memory Corruption in Core due to secure memory access by user while loading modem image. | |
| Modificada | Crítica (9.8) | 0.35% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+225 | 7/11/2023 | 17/6/2026 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | |
| Modificada | Media (5.9) | 0.35% | — | Xerox Primelink C9065 FirmwareXerox Primelink C9070 FirmwareXerox Primelink B9136 FirmwareXerox Primelink B9125 Firmware+89 | 2/11/2023 | 17/6/2026 | Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the… | |
| Modificada | Alta (8.8) | 0.43% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a hard-coded DES symmetric key, that can be… | |
| Modificada | Alta (8.8) | 0.45% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication. This issue allows an attacker to force the Android Client application to connect to a malicious MQTT broker, enabling it to send fake messages to the HMI device | |
| Modificada | Media (6.8) | 0.34% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power management or eventually the device secure settings (ADB debug). | |
| Modificada | Alta (8.8) | 0.12% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature is not configurable by the user. Due to… | |
| Modificada | Alta (8.8) | 0.39% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature is not configurable by the user. | |
| Modificada | Alta (7.8) | 0.19% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without requiring the physical access through USB. | |
| Modificada | Baja (3.3) | 0.18% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself. | |
| Modificada | Alta (7.8) | 0.20% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair | |
| Modificada | Alta (8.8) | 0.42% | — | Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware | 25/10/2023 | 17/6/2026 | The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug Bridge) protocol exposed on the network. | |
| Modificada | Alta (8.8) | 0.31% | — | Moxa Nport 5150ai-m12-ct-t FirmwareMoxa Nport 5250ai-m12-ct-t FirmwareMoxa Nport 5150ai-m12-t FirmwareMoxa Nport 5250ai-m12-t Firmware+104 | 3/10/2023 | 17/6/2026 | All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Wcn3991 Firmware+128 | 3/10/2023 | 17/6/2026 | Memory corruption in DSP Service during a remote call from HLOS to DSP. |