Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.46%—Checkpoint Mobile AccessCheckpoint Remote Access VPN6/8/202517/6/2026
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
AnalizadaMedia (5.4)0.23%—Checkpoint Mobile AccessCheckpoint Remote Access VPN27/4/202517/6/2026
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.
AnalizadaMedia (5.4)0.22%—Checkpoint Mobile AccessCheckpoint Remote Access VPN27/4/202517/6/2026
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
ModificadaAlta (7.2)27%—Checkpoint Mobile Access Portal Agent19/10/202117/6/2026
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.
ModificadaAlta (7.5)9.6%—Qualcomm Mobile Access Point15/10/202017/6/2026
The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This…
ModificadaMedia (5.5)61%—Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…