Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.47% | — | Zephyr-one Zephyr Project Manager | 3/10/2022 | 17/6/2026 | The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored… | |
| Modificada | Media (5.4) | 0.52% | — | Zephyr-one Zephyr Project Manager | 28/9/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Zephyr-one Zephyr Project Manager | 19/9/2022 | 17/6/2026 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections | |
| Modificada | Media (5.3) | 0.57% | — | Zephyrproject Zephyr | 31/8/2022 | 17/6/2026 | In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-bounds write a byte zero. | |
| Modificada | Alta (8.8) | 0.80% | — | Zephyrproject Zephyr | 26/7/2022 | 17/6/2026 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. | |
| Modificada | Alta (8.8) | 0.85% | — | Zephyrproject Zephyr | 26/7/2022 | 17/6/2026 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. | |
| Modificada | Baja (3.3) | 0.21% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh | |
| Modificada | Alta (7.8) | 0.21% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm | |
| Modificada | Baja (3.3) | 0.20% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp | |
| Modificada | Alta (7.5) | 0.89% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4 | |
| Modificada | Alta (7.5) | 0.89% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9 | |
| Modificada | Alta (7.5) | 0.89% | — | Zephyrproject Zephyr | 28/6/2022 | 17/6/2026 | Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr | |
| Modificada | Media (6.1) | 1.1% | — | Zephyr Project Manager Project Zephyr Project Manager | 13/6/2022 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (6.8) | 0.48% | — | Zephyrproject Zephyr | 7/2/2022 | 17/6/2026 | The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj | |
| Modificada | Alta (8.8) | 0.74% | — | Zephyrproject Zephyr | 7/2/2022 | 17/6/2026 | Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf | |
| Modificada | Alta (7.5) | 1.1% | — | Zephyrproject Zephyr | 19/10/2021 | 17/6/2026 | Disconnecting L2CAP channel right after invalid ATT request leads freeze. Zephyr versions >= 2.4.0, >= 2.5.0 contain Use After Free (CWE-416). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7g38-3x9v-v7vp | |
| Modificada | Alta (7.5) | 0.96% | — | Zephyrproject Zephyr | 19/10/2021 | 17/6/2026 | Truncated L2CAP K-frame causes assertion failure. Zephyr versions >= 2.4.0, >= v.2.50 contain Improper Handling of Length Parameter Inconsistency (CWE-130), Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fx88-6c29-vrp3 | |
| Modificada | Alta (8.8) | 0.61% | — | Zephyrproject Zephyr | 12/10/2021 | 17/6/2026 | RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Zephyr versions >= >=2.4.0 contain Out-of-bounds Write (CWE-787). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fj4r-373f-9456 | |
| Modificada | Crítica (9.8) | 0.92% | — | Zephyrproject Zephyr | 12/10/2021 | 17/6/2026 | Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (Wrap or Wraparound) (CWE-191). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-89j6-qpxf-pfpc | |
| Modificada | Media (6.5) | 0.54% | — | Zephyrproject Zephyr | 12/10/2021 | 17/6/2026 | Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p86r-gc4r-4mq3 | |
| Modificada | Alta (8.8) | 0.76% | — | Zephyrproject Zephyr | 12/10/2021 | 17/6/2026 | Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-w44j-66g7-xw99 | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Zephyrproject Zephyr | 5/10/2021 | 17/6/2026 | Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363 | |
| Modificada | Alta (8.8) | 0.35% | — | Zephyrproject Zephyr | 5/10/2021 | 17/6/2026 | Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q65-5gqf-fmw5 | |
| Modificada | Alta (7.5) | 0.96% | — | Zephyrproject Zephyr | 5/10/2021 | 17/6/2026 | Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4 | |
| Modificada | Media (6.5) | 0.98% | — | Zephyrproject Zephyr | 5/10/2021 | 17/6/2026 | BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see… |