Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.26% | — | Linuxfoundation Pytorch | 30/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real… | |
| Analizada | Crítica (9.8) | 0.48% | — | Linuxfoundation Pipecd | 21/3/2025 | 17/6/2026 | Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges. | |
| Analizada | Alta (7.4) | 0.38% | — | Linuxfoundation Kuadrant | 21/3/2025 | 17/6/2026 | Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster | |
| Aplazada | Crítica (9.8) | 1.1% | — | Linuxfoundation KedroAI | 20/3/2025 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve… | |
| Aplazada | Alta (8.8) | 1.1% | — | Linuxfoundation KedroAI | 20/3/2025 | 17/6/2026 | In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running… | |
| Analizada | Alta (7.8) | 0.29% | 💥 PoC | Linuxfoundation ContainerdDebian Linux | 17/3/2025 | 17/6/2026 | containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This… | |
| Aplazada | Media (6.2) | 0.16% | — | Open Networking Foundation Sd-ran OnosAILinuxfoundation Onos-lib-goAI | 16/3/2025 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits. | |
| Analizada | Baja (2) | 0.26% | — | Linuxfoundation Pytorch | 10/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity… | |
| Analizada | Baja (2.3) | 0.44% | — | Linuxfoundation Pytorch | 10/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fleetdm FleetAILinuxfoundation OsqueryAI | 6/3/2025 | 17/6/2026 | fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to… | |
| Analizada | Media (4.1) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 3/3/2025 | 17/6/2026 | In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062. | |
| Analizada | Media (6.8) | 0.11% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 3/3/2025 | 17/6/2026 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2061. | |
| Modificada | Media (6.6) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 3/2/2025 | 17/6/2026 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09403752; Issue ID: MSV-2434. | |
| Analizada | Media (5.3) | 0.21% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 3/2/2025 | 17/6/2026 | In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737,… | |
| Aplazada | Media (6.5) | 0.24% | — | Linuxfoundation MagmaAI | 22/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allow network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `RRC Establishment Clause` field. | |
| Aplazada | Alta (7.5) | 0.40% | — | Linuxfoundation MagmaAI | 21/1/2025 | 17/6/2026 | A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS… | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS… | |
| Analizada | Crítica (9.8) | 0.94% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Analizada | Alta (7.5) | 0.61% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS… | |
| Modificada | Alta (7.5) | 0.60% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet missing an expected `MME_UE_S1AP_ID` field. |