Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1713 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.10% | — | Samsung ManagedprovisioningAI | 2/10/2026 | 2/10/2026 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | |
| Aplazada | Alta (7) | 0.09% | — | Anjvision Yssd-rtmp-h5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption. | |
| Aplazada | Alta (8.7) | 0.29% | — | Anjvision Yssd-rtmp-h5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation. | |
| Aplazada | Media (6.9) | 0.19% | — | Anjvision Yssd Rtmp H5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries. | |
| Aplazada | Alta (7.2) | 0.34% | — | Anjvision Yssd Rtmp H5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the… | |
| Aplazada | Media (5.3) | 0.21% | — | Anjvision Yssd Rtmp H5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access. | |
| Aplazada | Alta (8.7) | 0.23% | — | Anjvision Yssd Rtmp H5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. | |
| Aplazada | Alta (8.7) | 0.18% | — | Anjvision Yssd-rtmp-h5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as… | |
| Aplazada | Alta (8.7) | 0.29% | — | Anjvision Yssd Rtmp H5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the… | |
| Aplazada | Crítica (9.3) | 0.33% | — | Anjvision Yssd-rtmp-h5AI | 29/9/2026 | 29/9/2026 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations. | |
| Aplazada | Alta (8.8) | 0.24% | — | Iron Mountain Archiving Services EnvisionAI | 28/9/2026 | 28/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Aplazada | Alta (7.8) | 0.20% | — | Geovision Gv-remote E-mapAI | 17/9/2026 | 18/9/2026 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully… | |
| Analizada | Media (5.5) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 14/9/2026 | 16/9/2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory. | |
| Analizada | Alta (7.5) | 0.47% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 14/9/2026 | 16/9/2026 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier. | |
| Analizada | Media (5.5) | 0.15% | — | Apple IpadosApple Iphone OSApple Visionos | 14/9/2026 | 16/9/2026 | A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able to access sensitive user data. | |
| Analizada | Media (6.5) | 0.47% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected process… | |
| Analizada | Crítica (9.1) | 0.40% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may… | |
| Analizada | Media (5.2) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 14/9/2026 | 15/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions. | |
| Analizada | Alta (7.3) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption. | |
| Analizada | Media (4.7) | 0.11% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination. | |
| Analizada | Alta (7.5) | 0.42% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 14/9/2026 | 16/9/2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user. | |
| Analizada | Media (5.5) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to read persistent device identifiers. | |
| Analizada | Alta (7.3) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption. |