Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisMedia (6.6)0.15%—FlightctlAI16/9/202617/9/2026
A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via…
Pendiente de análisisCrítica (9.1)0.50%—Nasa Core Flight SystemAI4/8/202631/8/2026
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
AnalizadaAlta (7.6)0.15%—Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+2074/8/20266/8/2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
AnalizadaMedia (6.5)0.17%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1404/8/20266/8/2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI30/7/202631/8/2026
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a…
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI16/7/202617/7/2026
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
AplazadaMedia (5.5)0.27%—Code-projects Simple Flight Ticket Booking SystemAI8/6/202623/7/2026
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has…
AnalizadaAlta (7.2)0.10%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+2141/6/202622/7/2026
Memory Corruption when processing fastboot commands to set display mode.
AnalizadaAlta (7.2)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+2691/6/202622/7/2026
Memory corruption while processing fastboot commands with improperly formatted input.
AnalizadaAlta (7.1)0.06%—Qualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 1 Mobile Platform FirmwareQualcomm Smart Audio 400 Platform Firmware+2131/6/202622/7/2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
AnalizadaAlta (7.2)0.10%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+2151/6/202622/7/2026
Memory corruption while processing fastboot commands with invalid input.
AnalizadaAlta (7.2)0.10%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+2111/6/202622/7/2026
Memory corruption while processing fastboot OEM commands.
AnalizadaAlta (7.2)0.10%—Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+2691/6/202622/7/2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
AnalizadaMedia (6.4)0.06%—Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+2321/6/202622/7/2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
AnalizadaMedia (5.5)0.09%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+1831/6/202622/7/2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
AplazadaAlta (7.5)0.42%—Flightphp FlightAI13/5/202617/6/2026
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the full exception message, exception code, and stack trace (including absolute filesystem paths) directly into the HTTP 500 response, with no debug gating. Production deployments leak internal paths,…
AplazadaAlta (7.5)0.41%—Flightphp FlightAI13/5/202617/6/2026
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_method'] parameter on any HTTP verb (including safe verbs such as GET), with no opt-in and no whitelist of permitted target methods. A GET request can…
AplazadaAlta (8.8)0.52%—Flightphp FlightAI13/5/202617/6/2026
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL statements by concatenating the $table argument and the keys of the $data array directly into the query, with no identifier quoting and no validation. When an application…
AplazadaMedia (4.4)0.16%—Flightphp FlightAI13/5/202617/6/2026
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supplied controller name, before Nette's class-name validation runs. The class-file write is correctly rejected by Nette when the name contains /, but the…
AplazadaAlta (8.6)0.50%—Flightphp FlightAI13/5/202617/6/2026
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query parameter directly into an application/javascript response body without validating that the value is a legal JavaScript identifier. An attacker can inject arbitrary JavaScript that executes in the response…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaAlta (7.8)0.07%—Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+1724/5/202629/6/2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
AnalizadaAlta (7.8)0.07%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/202630/9/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AnalizadaAlta (7.5)0.22%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2414/5/202630/9/2026
Transient DOS when processing target power rate tables during channel configuration.