Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1271 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.13%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaMedia (6)0.18%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.
AnalizadaMedia (6)0.30%—Mongodb C Driver20/5/202624/9/2026
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an…
Pendiente de análisisCrítica (9.3)0.80%💥 PoCAmazon Redshift-python-driverAI18/5/202623/7/2026
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
ModificadaCrítica (9.8)3.3%—Openjsf Webdriverio18/5/202624/7/2026
WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and…
Pendiente de análisisBaja (2)0.07%—AMD Mxgpu-virtualization DriverAI15/5/202617/6/2026
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system…
Pendiente de análisisBaja (1.8)0.10%—TEE SOC DriverAI15/5/202617/6/2026
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.
Pendiente de análisisMedia (6.8)0.10%—AMD Sensor Fusion HUB DriverAI15/5/202617/6/2026
A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash
Pendiente de análisisAlta (8.6)0.11%—AMD Raid DriverAI15/5/202617/6/2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.
Pendiente de análisisAlta (8.5)0.10%—AMD Chipset DriverAI15/5/202617/6/2026
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
Pendiente de análisisMedia (6.9)0.10%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash.
Pendiente de análisisMedia (6.9)0.11%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service
AnalizadaMedia (6)0.37%—Mongodb PHP Driver14/5/202624/9/2026
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
Pendiente de análisisMedia (5.6)0.18%💥 PoCNXP Moal.koAINXP Wi-fi DriverAI13/5/202617/6/2026
NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function.
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially…
Pendiente de análisisCrítica (9.3)0.13%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…
Pendiente de análisisMedia (6.9)0.10%—Intel NPU DriverAI12/5/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…
Pendiente de análisisMedia (5.4)0.08%—Intel NPU DriverAI12/5/202617/6/2026
Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This…
Pendiente de análisisMedia (6.8)0.10%—Windows Display Virtualization DriverAI12/5/202617/6/2026
Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via…
Pendiente de análisisCrítica (9.2)0.71%—Amazon Redshift Jdbc DriverAI8/5/202617/6/2026
An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a…
AnalizadaAlta (8.6)0.18%—Mongodb C Driver6/5/202618/6/2026
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.
ModificadaAlta (7.5)4.1%—Postgresql Jdbc Driver29/4/202611/9/2026
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough…
AnalizadaMedia (6.9)0.75%—Amazon EFS CSI Driver17/4/202617/6/2026
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to…
Pendiente de análisisMedia (5.4)0.14%💥 PoCAsus DriverhubAI16/4/202617/9/2026
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to…