Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
309 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+64 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Wcn6750 Firmware+64 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+77 | 2/5/2023 | 17/6/2026 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 Firmware+51 | 2/5/2023 | 17/6/2026 | Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key. | |
| Modificada | Crítica (9.8) | 2.0% | — | Max-tech Max-g866ac Firmware | 21/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a FirmwareQualcomm Qca6574au Firmware+38 | 13/4/2023 | 17/6/2026 | Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 Firmware+73 | 13/4/2023 | 17/6/2026 | Memory corruption due to use after free in Modem while modem initialization. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+110 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+222 | 13/4/2023 | 17/6/2026 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | |
| Modificada | Alta (8.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+124 | 13/4/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | |
| Modificada | Media (5.9) | 0.28% | — | Qualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Wcn6750 FirmwareQualcomm Wcn685x-5 Firmware+38 | 13/4/2023 | 17/6/2026 | Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 Firmware+97 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Media (6.5) | 0.31% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+116 | 11/4/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the… | |
| Modificada | Media (4.8) | 0.50% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+46 | 11/4/2023 | 17/6/2026 | Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network… | |
| Modificada | Media (5.5) | 0.15% | — | Supermicro X11ssl-cf FirmwareSupermicro X11dac FirmwareSupermicro X11dai-n FirmwareSupermicro X11ddw-l Firmware+142 | 7/4/2023 | 9/7/2026 | Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions. | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue results from the lack… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Vimeo plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IVI plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on TCP port 4044. The… | |
| Modificada | Alta (8.8) | 1.9% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Generic plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the YouTube plugin for the xupnpd service, which listens on TCP port 4044. The issue… |