Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+155 | 2/2/2026 | 17/6/2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 0.47% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters. | |
| Analizada | Crítica (9.8) | 0.51% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. | |
| Analizada | Crítica (9.8) | 0.51% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. | |
| Analizada | Crítica (9.8) | 0.49% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. | |
| Analizada | Media (4.8) | 0.35% | — | Opensecurity Mobile Security Framework | 27/1/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host`… | |
| Aplazada | Crítica (9.8) | 0.38% | — | Fmeaddons Registration Login With Mobile Phone Number FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registration & Login with Mobile Phone Number for WooCommerce: from n/a… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Registration Login With Mobile Phone NumberAI | 17/1/2026 | 17/6/2026 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_php_fun() function. This… | |
| Aplazada | Alta (8.5) | 0.17% | — | IfunboxAIApple Mobile Device ServiceAI | 16/1/2026 | 17/6/2026 | iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts. | |
| Aplazada | Media (4.4) | 0.27% | — | WMF Mobile RedirectorAI | 14/1/2026 | 17/6/2026 | The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Alta (8.5) | 0.26% | — | Wondershare Mobiletrans | 13/1/2026 | 17/6/2026 | Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with… | |
| Analizada | Alta (7.8) | 0.14% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+41 | 7/1/2026 | 7/10/2026 | Memory corruption occurs when a secure application is launched on a device with insufficient memory. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+41 | 7/1/2026 | 7/10/2026 | Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+41 | 7/1/2026 | 7/10/2026 | Memory corruption while passing pages to DSP with an unaligned starting address. | |
| Analizada | Media (5.5) | 0.13% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+171 | 7/1/2026 | 7/10/2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+200 | 7/1/2026 | 7/10/2026 | Memory corruption while processing identity credential operations in the trusted application. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Sa8145p FirmwareQualcomm Sa8150p FirmwareQualcomm Sa8155p FirmwareQualcomm Sa8195p Firmware+109 | 7/1/2026 | 7/10/2026 | Memory corruption while processing a secure logging command in the trusted application. | |
| Analizada | Alta (8.4) | 0.13% | — | Qualcomm Wcd9385 FirmwareQualcomm Wcd9390 FirmwareQualcomm Wcd9395 FirmwareQualcomm Wcn3950 Firmware+101 | 7/1/2026 | 7/10/2026 | Cryptographic issue may occur while encrypting license data. | |
| Analizada | Media (6.4) | 0.11% | — | Qualcomm Sa6155p FirmwareQualcomm Sa8155p FirmwareQualcomm Sa8195p FirmwareQualcomm Sm4635 Firmware+78 | 7/1/2026 | 7/10/2026 | Memory corruption while handling sensor utility operations. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+181 | 7/1/2026 | 7/10/2026 | Memory corruption while deinitializing a HDCP session. | |
| Analizada | Media (6.7) | 0.14% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6391 Firmware+60 | 7/1/2026 | 7/10/2026 | Memory corruption while accessing a synchronization object during concurrent operations. | |
| Analizada | Media (6.7) | 0.14% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6698aq Firmware+41 | 7/1/2026 | 7/10/2026 | Memory corruption while parsing clock configuration data for a specific hardware type. |