Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.7)0.11%—Mediatek MteeAI5/10/20266/10/2026
In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607.
Pendiente de análisisMedia (6.7)0.11%—Mediatek MteeAI5/10/20266/10/2026
In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608.
Pendiente de análisisMedia (6.7)0.11%—Mediatek ApusysAI5/10/20266/10/2026
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.
Pendiente de análisisMedia (5.3)0.18%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
Pendiente de análisisMedia (5.3)0.18%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
Pendiente de análisisMedia (6.7)0.12%—Mediatek CcciAI5/10/20266/10/2026
In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID:…
Pendiente de análisisMedia (5.3)0.20%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 /…
Pendiente de análisisMedia (5.3)0.20%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 /…
Pendiente de análisisAlta (8.4)0.13%—Mediatek APUAI5/10/20266/10/2026
In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
Pendiente de análisisAlta (8.4)0.13%—Mediatek NeuropilotAI5/10/20266/10/2026
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
Pendiente de análisisAlta (8.4)0.13%—Mediatek NeuropilotAI5/10/20266/10/2026
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.
Pendiente de análisisAlta (7.5)0.23%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
AnalizadaMedia (5.3)0.19%—Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+157/9/20269/9/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue…
AnalizadaMedia (5.3)0.19%—Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+537/9/20269/9/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue…
AnalizadaAlta (8.4)0.13%—Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+497/9/20269/9/2026
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
AnalizadaAlta (8.4)0.13%—Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+497/9/20269/9/2026
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.
AnalizadaMedia (5.5)0.09%—Mediatek Mt2716 FirmwareMediatek Mt6835 FirmwareMediatek Mt6858 FirmwareMediatek Mt6878 Firmware+187/9/20269/9/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
AplazadaCrítica (9.3)3.4%—Zbtlink We1326AIZbtlink We357AIZbtlink We5926AIZbtlink We5926 WDAI+1227/8/202624/9/2026
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated…
AnalizadaMedia (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8768 FirmwareMediatek Mt8791t FirmwareMediatek Mt8792 Firmware+63/8/202619/8/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
AnalizadaMedia (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+73/8/202619/8/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
AnalizadaMedia (4.4)0.15%—Mediatek Mt6983 FirmwareMediatek Mt8676 FirmwareMediatek Mt8678 FirmwareMediatek Mt8755 Firmware+133/8/202619/8/2026
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
AnalizadaAlta (7.8)0.15%—Mediatek Mt7925 FirmwareMediatek Mt7927 FirmwareMediatek Mt7902 FirmwareMediatek Mt7920 Firmware+23/8/202619/8/2026
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
AnalizadaMedia (5.5)0.15%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID:…
AnalizadaMedia (4.4)0.14%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
AnalizadaMedia (5.5)0.11%—Mediatek Mt6990 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 Firmware+23/8/202619/8/2026
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735,…