Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
841 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.42% | — | Agito Computer Health4allAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection. This issue affects Health4All: before 10.01.2025. | |
| Aplazada | Alta (8.3) | 0.44% | — | Agito Computer Health4allAI | 24/2/2025 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025. | |
| Aplazada | Alta (8.8) | 0.42% | — | Agito Computer Life4allAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection. This issue affects Life4All: before 10.01.2025. | |
| Modificada | Alta (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | |
| Analizada | Media (4.2) | 0.24% | — | VIMNetapp HCI Compute Node | 18/2/2025 | 17/6/2026 | Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a… | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+123 | 3/2/2025 | 17/6/2026 | Memory corruption while power-up or power-down sequence of the camera sensor. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+20 | 3/2/2025 | 17/6/2026 | Memory corruption may occour while generating test pattern due to negative indexing of display ID. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+28 | 3/2/2025 | 17/6/2026 | Memory corruption while handling IOCTL call from user-space to set latency level. | |
| Analizada | Alta (7) | 0.07% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+33 | 3/2/2025 | 17/6/2026 | Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+156 | 3/2/2025 | 17/6/2026 | Memory corruption while configuring a Hypervisor based input virtual device. | |
| Analizada | Alta (8.7) | 0.50% | — | Cvat Computer Vision Annotation Tool | 28/1/2025 | 17/6/2026 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT deployments that run any of the… | |
| Analizada | Media (5.5) | 0.28% | — | VIMNetapp HCI Compute Node Firmware | 20/1/2025 | 17/6/2026 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by… | |
| Aplazada | Media (6.9) | 0.42% | — | Virtual Computer Vysual RH SolutionAI | 14/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Virtual Computer Vysual RH Solution 2024.12.1. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Panel. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Alta (8.2) | 1.1% | 💥 PoC | Cs-grp NEO ImpactGreenware GreenguardHowyar SysreturnRadix Smart Recovery+3 | 14/1/2025 | 17/6/2026 | Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path. | |
| Analizada | Media (5.3) | 0.38% | — | Campcodes Computer Laboratory Management System | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. This affects an unknown part of the file /class/edit/edit. The manipulation of the argument s_lname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.47% | — | Campcodes Computer Laboratory Management System | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is some unknown functionality of the file /class/edit/edit. The manipulation of the argument e_photo leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Alta (8.8) | 0.51% | — | Oretnom23 Computer Laboratory Management System | 8/1/2025 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list. | |
| Aplazada | Baja (3.9) | 1.3% | 💥 PoC | Tubitak Bilgem Pardus OS MY ComputerAI | 6/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: before 0.7.2. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to read board data. | |
| Aplazada | Alta (8.8) | 0.49% | — | Quanta Computer QocaAI | 31/12/2024 | 17/6/2026 | The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation. | |
| Analizada | Alta (8.8) | 0.43% | — | Huawei Fusioncompute | 27/12/2024 | 17/6/2026 | There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability ID: HWPSIRT-2020-05010) This vulnerability… | |
| Analizada | Alta (7.8) | 0.11% | — | Huawei Fusioncompute | 27/12/2024 | 17/6/2026 | There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common… |