Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.25% | — | Divvydrive Information Technologies INC DivvydriveAI | 1/7/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1. | |
| Aplazada | Alta (8.2) | 0.20% | — | OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and… | |
| Analizada | Media (6.9) | 0.30% | — | Redhat PEN Drive | 26/6/2026 | 8/7/2026 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that… | |
| Analizada | Media (4.3) | 0.20% | — | Mattermost Google Drive | 25/6/2026 | 11/8/2026 | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | |
| Aplazada | Media (6.8) | 0.17% | 💥 PoC | Toshiba Generic IO Memory Access DriverAIDynabook Generic IO Memory Access DriverAI | 25/6/2026 | 25/6/2026 | Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory. | |
| Pendiente de análisis | Crítica (9.6) | 0.53% | — | Event Driven AnsibleAI | 23/6/2026 | 16/7/2026 | A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials… | |
| Aplazada | Alta (8.5) | 0.18% | — | Bdrive NetdriveAI | 19/6/2026 | 6/10/2026 | NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot,… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Realtek High Definition Audio DriverAI | 19/6/2026 | 29/9/2026 | Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service path. Attackers can insert an executable file in the unquoted path and restart the service to execute code with LocalSystem… | |
| Aplazada | Alta (8.1) | 0.44% | — | LuxedriveAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions. | |
| Aplazada | Alta (8.3) | 0.29% | — | Softlabbd Integrate Google DriveAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8. | |
| Aplazada | Alta (8.5) | 0.18% | — | Ricoh Printer DriversAIKonicaminolta Printer DriversAI | 15/6/2026 | 24/7/2026 | Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver. | |
| Aplazada | Alta (7.1) | 0.11% | — | Dvdfab Virtual DriveAI | 15/6/2026 | 24/7/2026 | A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.9) | 0.10% | — | Samsung Android USB Driver | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI | 29/5/2026 | 21/7/2026 | Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800… | |
| Analizada | Media (6.8) | 0.11% | — | Synology Beedrive | 27/5/2026 | 17/6/2026 | Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. | |
| Analizada | Alta (7.8) | 0.14% | — | Synology Beedrive | 27/5/2026 | 26/9/2026 | Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (4.7) | 0.09% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to denial of service. | |
| Pendiente de análisis | Media (5.6) | 0.15% | — | Nvidia GPU Display Driver FOR LinuxAI | 26/5/2026 | 24/7/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of service, data tampering,… | |
| Analizada | Media (6.5) | 0.16% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead… | |
| Analizada | Alta (7.1) | 0.17% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure. | |
| Analizada | Media (5.5) | 0.16% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.8) | 0.15% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. | |
| Analizada | Alta (7.8) | 0.20% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. | |
| Analizada | Alta (7.8) | 0.21% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code… | |
| Analizada | Alta (7.8) | 0.14% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. |