Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2884▼ 177 respecto a la semana anterior
Críticas / altas1281▼ 56 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 3.8% | — | Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+159 | 20/1/2026 | 17/6/2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. | |
| Analizada | Alta (8.9) | 5.9% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the argument params leads to buffer overflow. Remote exploitation of the attack is… | |
| Analizada | Alta (8.9) | 6.5% | — | Sgwbox N3 Firmware | 15/12/2025 | 30/9/2026 | A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Alta (8.9) | 19% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command injection. The attack may be initiated remotely. The exploit has been released… | |
| Analizada | Alta (8.9) | 19% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The… | |
| Analizada | Alta (8.9) | 17% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Analizada | Media (5.5) | 12% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early… | |
| Analizada | Media (5.5) | 0.68% | — | Sgwbox N3 Firmware | 15/12/2025 | 17/6/2026 | A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POST Message Handler. The manipulation of the argument token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fsm10056 FirmwareQualcomm Ipq5010 Firmware+133 | 5/9/2023 | 17/6/2026 | Memory Corruption in Core Platform while printing the response buffer in log. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fsm10056 FirmwareQualcomm Ipq5010 Firmware+132 | 5/9/2023 | 17/6/2026 | Memory corruption in Core Platform while printing the response buffer in log. | |
| Modificada | Alta (7.1) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+116 | 8/8/2023 | 17/6/2026 | Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+136 | 8/8/2023 | 17/6/2026 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. | |
| Modificada | Alta (7.1) | 0.11% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 Firmware+181 | 8/8/2023 | 17/6/2026 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | |
| Modificada | Crítica (9.8) | 0.43% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+200 | 8/8/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. | |
| Modificada | Alta (8.2) | 1.2% | — | Sick Ue410-en4 FirmwareSick Ue410-en3 FirmwareSick Ue410-en1 FirmwareSick Fx0-gpnt00030 Firmware+7 | 12/5/2023 | 17/6/2026 | Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the… | |
| Modificada | Crítica (9.8) | 0.62% | — | Sick Ue410-en3 FirmwareSick Ue410-en1 FirmwareSick Ue410-en3s04 FirmwareSick Ue410-en4 Firmware+6 | 19/4/2023 | 17/6/2026 | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (8.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+124 | 13/4/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Qca6390 Firmware+97 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8076 FirmwareQualcomm Apq8096au Firmware+280 | 10/3/2023 | 17/6/2026 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. | |
| Modificada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 Firmware+185 | 10/3/2023 | 17/6/2026 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+119 | 10/3/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. | |
| Modificada | Alta (7) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+136 | 10/3/2023 | 17/6/2026 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | |
| Modificada | Alta (7.8) | 0.14% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+153 | 10/3/2023 | 17/6/2026 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. |