Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1219 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.21% | — | Netx DUO Mqtt ClientAI | 29/9/2026 | 30/9/2026 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on… | |
| Pendiente de análisis | Media (4.5) | 0.34% | — | QT VNC ServerAI | 24/9/2026 | 24/9/2026 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the… | |
| En análisis | Media (5.3) | 0.13% | — | RabbitmqAIRabbitmq WEB MqttAIRabbitmq WEB StompAI | 23/9/2026 | 24/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl:102) validates the Origin header on… | |
| En análisis | Alta (8.2) | 0.37% | — | RabbitmqAIRabbitmq WEB MqttAI | 23/9/2026 | 24/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does not set max_frame_size, so cowboy's default of infinity applies. cowlib's… | |
| Pendiente de análisis | Baja (2.3) | 0.25% | — | QT Group QTAI | 23/9/2026 | 24/9/2026 | Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document. | |
| Pendiente de análisis | Baja (0.6) | 0.10% | — | QT QuickAI | 23/9/2026 | 24/9/2026 | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. | |
| Pendiente de análisis | Crítica (9.3) | 0.53% | — | LwipAIMqttAI | 22/9/2026 | 23/9/2026 | lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Analizada | Alta (7) | 0.06% | — | Qualcomm Wsa8845h FirmwareQualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 Firmware+39 | 17/9/2026 | 22/9/2026 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | |
| Pendiente de análisis | Media (4.6) | 0.67% | — | QT Group QTAI | 16/9/2026 | 18/9/2026 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excessively large Cache-Control header value returned by an… | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | QT QdomdocumentAI | 16/9/2026 | 18/9/2026 | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input. | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | QT NFCAI | 11/9/2026 | 18/9/2026 | An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag. | |
| Aplazada | Alta (7.1) | 0.39% | — | QtbaseAIQtxmlAI | 8/9/2026 | 11/9/2026 | Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Toktok QtoxAI | 26/8/2026 | 9/9/2026 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | |
| Aplazada | Alta (8) | 0.57% | — | Zigbee2mqttAI | 5/8/2026 | 26/8/2026 | Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. The extension handler only validates that the name ends in… | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Analizada | Media (6.7) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+48 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | |
| Aplazada | Alta (8.6) | 0.46% | — | QTI NeonAI | 28/7/2026 | 30/7/2026 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No… | |
| Aplazada | Baja (2.9) | 0.44% | — | QTAI | 23/7/2026 | 23/7/2026 | Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default… | |
| Aplazada | Alta (7.1) | 0.16% | — | Linux-gaming PortprotonqtAIGnome NetworkmanagerAI | 23/7/2026 | 23/7/2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. | |
| Aplazada | Media (6.3) | 0.30% | — | Qt5compatAIQtbaseAI | 21/7/2026 | 23/7/2026 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases… | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+43 | 6/7/2026 | 7/7/2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | |
| Aplazada | Alta (7.8) | 0.72% | — | Liambindle Mqtt-cAI | 14/6/2026 | 10/8/2026 | LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed… | |
| Modificada | Media (6.1) | 0.98% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build… |