Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3238▲ 694 respecto a la semana anterior
Críticas / altas1520▲ 133 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
3971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.55% | — | Microsoft Malware Protection Platform | 14/4/2023 | 17/6/2026 | Microsoft Defender Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Qca6595 FirmwareQualcomm Qca6595au FirmwareQualcomm Qca6696 FirmwareQualcomm Sa6150p Firmware+12 | 13/4/2023 | 17/6/2026 | Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 Firmware+73 | 13/4/2023 | 17/6/2026 | Memory corruption due to use after free in Modem while modem initialization. | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm Qca6310 FirmwareQualcomm Qca6320 FirmwareQualcomm Sd835 FirmwareQualcomm Snapdragon 835 Mobile Platform Firmware+6 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer overread in Linux sensors | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+110 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+222 | 13/4/2023 | 17/6/2026 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | |
| Modificada | Alta (8.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+124 | 13/4/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Ar8031 Firmware+35 | 13/4/2023 | 17/6/2026 | Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 Firmware+97 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Mdm8207 Firmware+22 | 13/4/2023 | 17/6/2026 | Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm8207 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 Firmware+23 | 13/4/2023 | 17/6/2026 | Information disclosure in modem due to improper check of IP type while processing DNS server query | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9207 FirmwareQualcomm Wcn685x-1 Firmware+22 | 13/4/2023 | 17/6/2026 | Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet | |
| Modificada | Media (5.4) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images… | |
| Modificada | Media (4.6) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the… | |
| Modificada | Media (5.3) | 0.42% | — | SAP Abap Platform KernelSAP WEB Dispatcher | 11/4/2023 | 17/6/2026 | The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources. | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Alta (7.1) | 1.1% | — | IBM Tririga Application Platform | 7/4/2023 | 17/6/2026 | IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Tririga Application Platform | 7/4/2023 | 17/6/2026 | IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 241036. | |
| Modificada | Media (5.4) | 0.43% | — | Dell Streaming Data Platform | 5/4/2023 | 17/6/2026 | Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks. | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 29/3/2023 | 17/6/2026 | A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users. |