Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.08%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2718/7/202517/6/2026
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+2428/7/202517/6/2026
Memory corruption while retrieving the CBOR data from TA.
AnalizadaAlta (8.2)0.22%—Qualcomm Sm6250 FirmwareQualcomm Sm6370 FirmwareQualcomm Sm7315 FirmwareQualcomm Sm7325p Firmware+1758/7/202517/6/2026
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
AnalizadaAlta (7.8)0.10%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2178/7/202517/6/2026
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1858/7/202517/6/2026
Memory corruption while operating the mailbox in Automotive.
AplazadaBaja (2.1)0.14%—QtnetworkAI11/6/202529/7/2026
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error…
AplazadaAlta (7.1)0.28%—Redqteam WishlistAI9/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Wishlist wishlist allows Reflected XSS.This issue affects Wishlist: from n/a through <= 2.1.0.
AnalizadaAlta (8.7)0.95%—Qnap QTSQnap Quts Hero6/6/202517/6/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321…
AnalizadaMedia (5.3)0.42%—Qnap QTSQnap Quts Hero6/6/202517/6/2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build…
ModificadaMedia (5.1)0.24%—QT5/6/202529/7/2026
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
AnalizadaAlta (8.6)0.84%⚠ Explotación activa💥 PoCQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+713/6/202517/6/2026
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
AnalizadaAlta (8.6)0.46%⚠ Explotación activaQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+723/6/202517/6/2026
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
AnalizadaAlta (8.2)0.30%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2213/6/202517/6/2026
Information disclosure may occur while processing goodbye RTCP packet from network.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
AnalizadaMedia (6.6)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+873/6/202517/6/2026
Memory corruption while processing IOCTL command to handle buffers associated with a session.
AnalizadaAlta (7.8)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1893/6/202517/6/2026
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
AplazadaAlta (8.4)0.38%—QtcoreAI2/6/202529/7/2026
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was…
AplazadaMedia (4.3)0.28%—Redqteam WishlistAI16/5/202517/6/2026
Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist: from n/a through <= 2.1.0.
AplazadaMedia (4.3)0.34%—Redqteam WishlistAI16/5/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist allows Retrieve Embedded Sensitive Data.This issue affects Wishlist: from n/a through <= 2.1.0.
AplazadaAlta (7.3)0.20%—QTAI16/5/202529/7/2026
Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be…
AplazadaMedia (6)0.13%—Pcvue Mqtt Add-onAI6/5/202517/6/2026
The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+366/5/202517/6/2026
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+296/5/202517/6/2026
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2626/5/202517/6/2026
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.