Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
8594 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wsa8845h FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+16 | 17/9/2026 | 22/9/2026 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+20 | 17/9/2026 | 22/9/2026 | Memory corruption while processing rear sensor IOCTL calls. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+148 | 17/9/2026 | 22/9/2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |
| Analizada | Alta (7) | 0.06% | — | Qualcomm Wsa8845h FirmwareQualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 Firmware+39 | 17/9/2026 | 22/9/2026 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Iqx5121 FirmwareQualcomm Iqx7181 FirmwareQualcomm Qca0000 FirmwareQualcomm Qcm5430 Firmware+21 | 17/9/2026 | 22/9/2026 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+10 | 17/9/2026 | 22/9/2026 | Memory Corruption when copying large input data exceeds normal allocation limits. | |
| Aplazada | Alta (7.2) | 0.50% | — | Yeti-platform YetiAI | 16/9/2026 | 23/9/2026 | Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects. | |
| Aplazada | Alta (7.1) | 0.40% | — | Tduck Survey FormAI | 16/9/2026 | 24/9/2026 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses. | |
| Aplazada | Alta (8.7) | 0.91% | — | Zlt2000 Microservices-platformAI | 16/9/2026 | 16/9/2026 | zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role… | |
| Aplazada | Alta (7.1) | 0.42% | — | Tduck Survey FormAI | 16/9/2026 | 24/9/2026 | TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses… | |
| Aplazada | Alta (7.2) | 0.54% | — | Zlt2000 Microservices-platformAI | 16/9/2026 | 24/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying… | |
| Aplazada | Alta (7.1) | 0.48% | — | Zlt2000 Microservices-platformAIElasticsearchAI | 16/9/2026 | 18/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers… | |
| Aplazada | Alta (8.7) | 0.46% | — | Zlt2000 Microservices-platformAI | 16/9/2026 | 21/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password… | |
| Aplazada | Media (4.8) | 0.19% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 16/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side… | |
| Aplazada | Media (4.3) | 0.14% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 17/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view… | |
| Aplazada | Crítica (9.8) | 0.52% | 💥 PoC | Crocoblock JetformbuilderAI | 16/9/2026 | 17/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful… | |
| Aplazada | Crítica (9) | 0.37% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the… | |
| Aplazada | Alta (7.4) | 0.32% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful… | |
| Aplazada | Alta (7.9) | 0.25% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful… |