Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+3159/10/202517/6/2026
Memory corruption during PlayReady APP usecase while processing TA commands.
AnalizadaMedia (6.5)0.08%—Qualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform Firmware+619/10/202517/6/2026
Information disclosure may occur while processing the hypervisor log.
AnalizadaAlta (8.8)0.09%—Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+219/10/202530/9/2026
Memory corruption while performing SCM call.
AnalizadaAlta (7.5)0.22%—Qualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform FirmwareQualcomm Ipq5300 Firmware+6324/9/202517/6/2026
Transient DOS while processing power control requests with invalid antenna or stream values.
AnalizadaAlta (7.5)0.24%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Ipq8076a FirmwareQualcomm Ipq8078 Firmware+11624/9/202517/6/2026
Transient DOS while handling command data during power control processing.
AnalizadaAlta (7.5)0.21%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+19924/9/202517/6/2026
Transient DOS while parsing the EPTM test control message to get the test pattern.
AnalizadaAlta (7.1)0.08%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+28324/9/202525/9/2026
Cryptographic issue while performing RSA PKCS padding decoding.
ModificadaCrítica (9.8)0.69%💥 PoCInspirythemes Realhomes3/9/202517/6/2026
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.
AnalizadaAlta (8.1)1.6%💥 ExploitEsphome Firmware2/9/202517/6/2026
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows…
AplazadaAlta (8.6)0.35%—Home-assistant Tapo ControlAI14/8/202517/6/2026
HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions…
AplazadaMedia (6.5)0.26%—Phome EmpirebakAI14/8/202517/6/2026
An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file was loaded.
AnalizadaAlta (7.8)0.11%—Dell Supportassist FOR Home PCS14/8/202517/6/2026
SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AnalizadaAlta (7.8)0.11%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS14/8/202517/6/2026
SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
AnalizadaAlta (7.5)0.21%—Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+1666/8/202517/6/2026
Transient DOS while creating NDP instance.
AnalizadaAlta (7.5)0.28%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3686/8/202517/6/2026
Transient DOS while processing an ANQP message.
AnalizadaAlta (7.5)0.21%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1466/8/202517/6/2026
Transient DOS while processing a frame with malformed shared-key descriptor.
AnalizadaMedia (6.5)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+3456/8/202517/6/2026
Information disclosure while processing the hash segment in an MBN file.
AnalizadaMedia (6.5)0.09%—Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+3386/8/202517/6/2026
Information disclosure while reading data from an image using specified offset and size parameters.
AplazadaAlta (7.8)0.19%—Chargepoint Home FlexAI1/8/202517/6/2026
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.
ModificadaAlta (7.8)0.15%💥 PoCAziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware30/7/20255/7/2026
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in…
AplazadaCrítica (9.8)2.1%—Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute…
AplazadaCrítica (9.1)0.49%—Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
AplazadaCrítica (9.4)0.28%💥 PoCGardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack.…
AplazadaMedia (4.1)0.29%💥 PoCFiberhome Fd602gw-dx-r410AI9/7/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is triggered via user-supplied input in the ping…
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.