Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

232 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.13%—Qualcomm Pm3003aQualcomm Pm6125Qualcomm Pm6150Qualcomm Pm6150a+16121/1/202117/6/2026
Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
ModificadaMedia (6.7)0.21%—Qualcomm Aqt1000Qualcomm Ar8031Qualcomm Ar8035Qualcomm Csra6620+27621/1/202117/6/2026
Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
ModificadaMedia (6.7)0.21%—Qualcomm Apq8053Qualcomm Apq8096auQualcomm Aqt1000Qualcomm Ar8031+28921/1/202117/6/2026
Out of bound access due to usage of an out-of-range pointer offset in the camera driver. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
ModificadaMedia (6.7)0.21%—Qualcomm Apq8017Qualcomm Apq8053Qualcomm Msm8917Qualcomm Msm8953+24221/1/202117/6/2026
Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggered and callback instance is deleted in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
ModificadaAlta (7.8)0.21%—Qualcomm Apq8076Qualcomm Aqt1000Qualcomm Ar8031Qualcomm Ar8035+31021/1/202117/6/2026
Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
ModificadaAlta (7.5)0.78%—Qualcomm Apq8009Qualcomm Apq8009wQualcomm Apq8017Qualcomm Apq8037+40921/1/202117/6/2026
Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaCrítica (9.1)0.88%—Qualcomm Apq8009Qualcomm Apq8009wQualcomm Apq8017Qualcomm Apq8037+41021/1/202117/6/2026
Buffer over-read while UE process invalid DL ROHC packet for decompression due to lack of check of size of compresses packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
ModificadaCrítica (9.8)1.1%—Qualcomm Apq8009Qualcomm Apq8017Qualcomm Apq8030Qualcomm Apq8037+49021/1/202117/6/2026
Out of bound memory access during music playback with modified content due to copying data without checking destination buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaCrítica (9.8)1.1%—Qualcomm Apq8017Qualcomm Apq8037Qualcomm Apq8052Qualcomm Apq8053+44521/1/202117/6/2026
Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…
ModificadaAlta (7.5)0.78%—Qualcomm Apq8017Qualcomm Apq8037Qualcomm Apq8052Qualcomm Apq8053+40821/1/202117/6/2026
Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…
ModificadaCrítica (9.8)1.1%—Qualcomm Apq8009Qualcomm Apq8009wQualcomm Apq8017Qualcomm Apq8030+48721/1/202117/6/2026
Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaCrítica (9.8)1.1%—Qualcomm Apq8009Qualcomm Apq8009wQualcomm Apq8017Qualcomm Apq8030+48721/1/202117/6/2026
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
ModificadaCrítica (9.8)1.1%—Qualcomm Apq8009Qualcomm Apq8009wQualcomm Apq8017Qualcomm Apq8030+50221/1/202117/6/2026
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory requirement in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaAlta (7.5)0.77%—Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8076 Firmware+46721/1/202117/6/2026
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
ModificadaCrítica (9.8)2.3%—Mitsubishielectric Qj71mes96 FirmwareMitsubishielectric Qj71ws96 FirmwareMitsubishielectric Q06ccpu-v FirmwareMitsubishielectric Q24dhccpu-v Firmware+915/10/202017/6/2026
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
ModificadaAlta (7.5)2.0%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1222/7/202017/6/2026
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
ModificadaMedia (6.5)0.94%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+814/5/202017/6/2026
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
ModificadaCrítica (9.8)2.5%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1026/3/202017/6/2026
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
ModificadaMedia (6.5)1.9%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1124/1/202017/6/2026
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
ModificadaCrítica (9.8)1.9%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1020/11/201917/6/2026
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
ModificadaMedia (6.5)1.4%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+617/9/201917/6/2026
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.
ModificadaAlta (7.5)1.7%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+1017/9/201917/6/2026
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
ModificadaAlta (8.8)1.9%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+617/9/201917/6/2026
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
ModificadaCrítica (9.8)5.8%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
ModificadaAlta (7.5)3.2%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.