Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+71 | 17/9/2026 | 22/9/2026 | Transient DOS while parsing frame during channel usage. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+148 | 17/9/2026 | 22/9/2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |
| Analizada | Media (5.4) | 0.09% | — | Intel Connectivity Performance Suite | 12/5/2026 | 21/7/2026 | Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Analizada | Media (5.6) | 0.14% | — | Airbus Tetra Connectivity Server | 3/4/2026 | 24/7/2026 | Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects TETRA connectivity… | |
| Analizada | Alta (8.3) | 0.40% | — | Broadcom Brocade Active Support Connectivity Gateway | 3/3/2026 | 17/6/2026 | Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric. | |
| Aplazada | Alta (7.3) | 0.13% | — | Intel Connectivity Performance SuiteAI | 12/8/2025 | 17/6/2026 | Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (8.6) | 0.16% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036. | |
| Analizada | Alta (7.1) | 0.24% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
| Aplazada | Media (5.7) | 0.21% | — | Redhat Connectivity LinkAILinuxfoundation KuadrantAI | 9/6/2025 | 17/6/2026 | The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those secrets over HTTP… | |
| Aplazada | Media (5.3) | 0.15% | — | Intel Integrated Connectivity I O Interface CnviAIIntel Core Ultra ProcessorsAI | 13/5/2025 | 17/6/2026 | Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Analizada | Alta (7.6) | 0.37% | — | Broadcom Brocade Active Support Connectivity Gateway | 28/2/2025 | 17/6/2026 | Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens… | |
| Modificada | Alta (8.6) | 0.59% | — | Amazon WEB Services Redshift Java Database Connectivity Driver | 24/12/2024 | 17/6/2026 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30. | |
| Aplazada | Alta (7.5) | 0.55% | — | Connectivity Standards Alliance MatterAI | 18/12/2024 | 17/6/2026 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion). | |
| Analizada | Media (5.1) | 0.35% | — | F5 Nginx API Connectivity ManagerF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Openid Connect | 6/11/2024 | 17/6/2026 | A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Connectivity Performance SuiteAI | 14/8/2024 | 17/6/2026 | Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.8) | 1.7% | — | Laurelbridge Dicom Connectivity FrameworkAI | 1/3/2024 | 17/6/2026 | Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file. | |
| Modificada | Media (5.3) | 0.36% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication. | |
| Modificada | Media (4.7) | 0.24% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline. | |
| Modificada | Alta (7.8) | 0.24% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. | |
| Modificada | Alta (7.3) | 0.20% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to… | |
| Modificada | Alta (7.5) | 0.44% | — | GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 30/11/2023 | 17/6/2026 | KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect. | |
| Modificada | Crítica (9.1) | 0.96% | — | GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 30/11/2023 | 17/6/2026 | KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information. | |
| Modificada | Alta (7.5) | 0.61% | — | Intel Connectivity Performance Suite | 14/11/2023 | 17/6/2026 | Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Media (5.7) | 0.29% | — | SAP Digital ManufacturingSAP Plant Connectivity | 13/6/2023 | 17/6/2026 | SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests… |