Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.23%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+2078/7/202517/6/2026
Transient DOS while handling beacon frames with invalid IE header length.
AnalizadaAlta (7.8)0.09%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2028/7/202517/6/2026
Memory corruption while processing manipulated payload in video firmware.
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption while processing video packets received from video firmware.
AnalizadaAlta (7.5)0.22%—Qualcomm Sa8620p FirmwareQualcomm Sa8650p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa8775p Firmware+1888/7/202517/6/2026
Transient DOS while processing received beacon frame.
AnalizadaAlta (7.5)0.22%—Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+1818/7/202517/6/2026
Transient DOS may occur while processing malformed length field in SSID IEs.
AnalizadaAlta (7.5)0.22%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 FirmwareQualcomm Immersive Home 216 Firmware+2368/7/202517/6/2026
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
AnalizadaMedia (5.5)0.08%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2718/7/202517/6/2026
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
ModificadaCrítica (9.8)0.38%—Inspirythemes Realhomes4/7/202517/6/2026
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.4.0.
AplazadaAlta (7.1)0.26%—Favethemes HomeyAI4/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey homey allows Reflected XSS.This issue affects Homey: from n/a through <= 2.4.5.
AplazadaMedia (5.3)0.30%—Sysadminsmedia HomeboxAI2/7/202517/6/2026
HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and deleting inventory item attachments. This flaw allows authenticated users to perform unauthorized actions on inventory item attachments that they do not…
AplazadaAlta (8.8)0.81%—Home Villas Real Estate Wordpress ThemeAI2/7/202517/6/2026
The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wp_rem_cs_widget_file_delete' function in all versions up to, and including, 2.8. This makes it possible for authenticated attackers, with Subscriber-level access…
AnalizadaBaja (2.1)0.40%—Phpgurukul OLD AGE Home Management System30/6/202517/6/2026
A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-scdetails.php. The manipulation of the argument emeradd leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaBaja (2.1)0.43%—Phpgurukul OLD AGE Home Management System30/6/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/edit-services.php. The manipulation of the argument sertitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaCrítica (9.3)0.32%—Favethemes HomeyAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey homey allows SQL Injection.This issue affects Homey: from n/a through <= 2.4.7.
ModificadaMedia (4.3)0.17%—Coolrunner Homerunner26/6/202517/6/2026
The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.30. This is due to missing or incorrect nonce validation on the main_settings() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted…
AplazadaAlta (7.1)0.13%—Jatinder PAL Singh BP Profile AS HomepageAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allows Stored XSS.This issue affects BP Profile as Homepage: from n/a through <= 1.1.
AplazadaAlta (7.5)0.74%—Choicehomemortgage AI Mortgage CalculatorAI6/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in choicehomemortgage AI Mortgage Calculator allows PHP Local File Inclusion. This issue affects AI Mortgage Calculator: from n/a through 1.0.1.
AnalizadaAlta (7.5)0.24%—Qualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform FirmwareQualcomm Ipq5300 Firmware+633/6/202517/6/2026
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
AnalizadaAlta (7.5)0.23%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+2073/6/202517/6/2026
Transient DOS while processing the EHT operation IE in the received beacon frame.
ModificadaMedia (5.4)0.25%—Phpgurukul OLD AGE Home Management System23/5/202517/6/2026
PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
AplazadaMedia (4.7)0.21%—Ecovacs HomeAIAlibaba Object Storage ServiceAI23/5/202517/6/2026
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.
AplazadaMedia (6.1)0.23%—Oaooa PichomeAI14/5/202517/6/2026
Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the login form. An attacker can inject malicious JavaScript code into the username or password fields during the login process
AplazadaAlta (8.8)0.62%—Homebrew JANAI9/5/202517/6/2026
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().
AplazadaAlta (7.3)0.28%—Patch MY PC Home UpdaterAI9/5/202517/6/2026
A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library…
AnalizadaMedia (4.3)0.24%—Favethemes Homey2/5/202517/6/2026
The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the 'homey_delete_user_account' action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…