Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
26.291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.14% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses… | |
| Analizada | Baja (3.3) | 0.13% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time `memcmp()`… | |
| Analizada | Baja (3.3) | 0.13% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time… | |
| Analizada | Alta (7.3) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+56 | 6/7/2026 | 29/9/2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. | |
| Analizada | Baja (3.3) | 0.15% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. Version 4.11.0 contains a patch. No known… | |
| Analizada | Media (5.5) | 0.15% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a… | |
| Analizada | Alta (8.8) | 0.36% | — | UI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition FirmwareUI Unifi Dream Machine PRO MAX FirmwareUI Unifi Dream Machine Beast Firmware+15 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device. | |
| Analizada | Alta (7.5) | 0.50% | — | UI Protect Floodlight Firmware | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight. | |
| En análisis | Media (6.1) | 0.27% | — | UI Unifi OS ServerUI Unifi Dream Machine Beast FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+26 | 2/7/2026 | 9/7/2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Dream Machine Beast FirmwareUI Enterprise Fortress Gateway FirmwareUI Unifi Dream Router FirmwareUI Unifi Dream Wall Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Media (6.8) | 1.1% | — | Tp-link Tl-wr841n Firmware | 29/6/2026 | 1/7/2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process. Successful exploitation… | |
| Analizada | Alta (7.4) | 5.5% | — | Dlink Dcs-935l Firmware | 29/6/2026 | 30/6/2026 | A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.4) | 0.44% | — | Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware | 26/6/2026 | 6/7/2026 | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and… | |
| Analizada | Crítica (9.3) | 0.57% | — | Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware | 26/6/2026 | 6/7/2026 | The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access. | |
| Analizada | Crítica (9.3) | 0.68% | — | Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware | 26/6/2026 | 6/7/2026 | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths. | |
| Analizada | Media (6.9) | 0.43% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service. | |
| Analizada | Alta (8.6) | 1.7% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable… | |
| Analizada | Alta (8.7) | 0.46% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. | |
| Analizada | Media (6.7) | 0.16% | — | Schneider-electric Easylogic T150 FirmwareSchneider-electric Saitel DP Firmware | 25/6/2026 | 14/7/2026 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files. | |
| Analizada | Alta (8.7) | 0.41% | — | Schneider-electric Easylogic T150 FirmwareSchneider-electric Saitel DP Firmware | 25/6/2026 | 14/7/2026 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have… |