Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.13%—Huawei Mate 20 PRO FirmwareHuawei Mate 20 PRO (ud) FirmwareHuawei Nova 5I Firmware27/12/202417/6/2026
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272) This vulnerability has been assigned…
AnalizadaBaja (3.3)0.12%—Huawei Mate 20 PRO Firmware20/12/202417/6/2026
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has…
ModificadaMedia (4.6)0.21%—Huawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Hima-l29c FirmwareHuawei Laya-al00ep Firmware+213/7/202117/6/2026
There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname.…
ModificadaAlta (7.8)0.83%—Huawei Honor 20 PRO FirmwareHuawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X Firmware+97/12/202017/6/2026
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege,…
ModificadaMedia (6.8)0.23%—Huawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X FirmwareHuawei P30 Firmware+611/8/202017/6/2026
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30…
ModificadaMedia (5.3)0.32%—Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+4327/4/202017/6/2026
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2…
ModificadaMedia (5.3)0.32%—Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+4327/4/202017/6/2026
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1…
ModificadaAlta (8.8)6.1%—Google AndroidHuawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X Firmware+1813/2/202017/6/2026
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…
ModificadaMedia (4.6)0.25%—Huawei Mate 20 PRO Firmware9/1/202017/6/2026
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow…
ModificadaAlta (7.8)0.60%—Huawei Mate 20 PRO Firmware13/12/201917/6/2026
Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode…
ModificadaAlta (8.1)2.7%—Google AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…