Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+114/2/202417/6/2026
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)0.35%—Silabs Gecko Software Development KIT5/2/202417/6/2026
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
ModificadaAlta (7.5)0.61%💥 PoCSilabs Gecko Software Development KIT2/2/202417/6/2026
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
ModificadaAlta (7.8)0.25%—Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure12/1/202417/6/2026
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.8)0.27%—Silabs Gecko Software Development KIT3/1/202417/6/2026
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.
ModificadaCrítica (9.8)0.40%—Silabs Gecko Software Development KIT2/1/202417/6/2026
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
ModificadaMedia (5.5)0.18%—Mediatek Software Development KIT2/1/202417/6/2026
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.
ModificadaBaja (3.3)0.38%—Amazon AWS Software Development KIT22/12/202317/6/2026
AWS SDK for PHP is the Amazon Web Services software development kit for PHP. Within the scope of requests to S3 object keys and/or prefixes containing a Unix double-dot, a URI path traversal is possible. The issue exists in the `buildEndpoint` method in the RestSerializer component of the AWS SDK for PHP v3 prior to…
ModificadaAlta (7.5)0.30%—Silabs Gecko Software Development KIT21/12/202317/6/2026
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
ModificadaCrítica (9.1)0.57%—Silabs Gecko Software Development KIT15/12/202317/6/2026
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.
ModificadaMedia (6.5)0.35%—Silabs Z-wave Software Development KIT15/12/202317/6/2026
A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.
ModificadaAlta (7.5)0.70%—Softing OPCSofting OPC UA C++ Software Development KITSofting Secure Integration Server14/12/202317/6/2026
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.
ModificadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.8)0.99%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.60%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (4.9)0.57%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
ModificadaMedia (4.7)0.71%—Microsoft Azure Machine Learning Software Development KIT12/12/202317/6/2026
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
ModificadaMedia (5.5)0.26%—Samsung Account WEB Software Development KIT5/12/202317/6/2026
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
ModificadaAlta (7.8)0.28%—Amazon FreertosTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+221/11/202317/6/2026
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
ModificadaAlta (7.8)0.28%—Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+221/11/202317/6/2026
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
ModificadaAlta (7.8)0.28%—Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+220/11/202317/6/2026
Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code execution.
ModificadaAlta (7.8)0.28%—Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+220/11/202317/6/2026
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.85%—Zoom MeetingsZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.