Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.46% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 6/8/2025 | 17/6/2026 | The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway. | |
| Analizada | Media (5.4) | 0.23% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 27/4/2025 | 17/6/2026 | For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties. | |
| Analizada | Media (5.4) | 0.22% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 27/4/2025 | 17/6/2026 | Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list. | |
| Modificada | Alta (7.2) | 27% | — | Checkpoint Mobile Access Portal Agent | 19/10/2021 | 17/6/2026 | Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent. | |
| Modificada | Alta (7.5) | 9.6% | — | Qualcomm Mobile Access Point | 15/10/2020 | 17/6/2026 | The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This… | |
| Modificada | Media (5.5) | 61% | — | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… |