Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1540 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.22%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaAlta (8.8)0.19%—Nvidia GPU Display Driver26/5/202620/7/2026
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaMedia (6.5)0.13%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaMedia (6)0.18%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.
AnalizadaMedia (6)0.30%—Mongodb C Driver20/5/202624/9/2026
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an…
Pendiente de análisisCrítica (9.3)0.80%💥 PoCAmazon Redshift-python-driverAI18/5/202623/7/2026
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
ModificadaCrítica (9.8)3.3%—Openjsf Webdriverio18/5/202624/7/2026
WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and…
AplazadaAlta (8.7)0.64%—Google Drive FOR WordpressAI17/5/202617/6/2026
Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name…
AplazadaAlta (8.5)0.12%—Privacy DriveAI16/5/202617/6/2026
Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with LocalSystem…
Pendiente de análisisBaja (2)0.07%—AMD Mxgpu-virtualization DriverAI15/5/202617/6/2026
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system…
Pendiente de análisisBaja (1.8)0.10%—TEE SOC DriverAI15/5/202617/6/2026
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.
Pendiente de análisisMedia (6.8)0.10%—AMD Sensor Fusion HUB DriverAI15/5/202617/6/2026
A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash
Pendiente de análisisAlta (8.6)0.11%—AMD Raid DriverAI15/5/202617/6/2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.
Pendiente de análisisAlta (8.5)0.10%—AMD Chipset DriverAI15/5/202617/6/2026
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
Pendiente de análisisMedia (6.9)0.10%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash.
Pendiente de análisisMedia (6.9)0.11%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service
Pendiente de análisisMedia (4.6)0.11%—AMD OverdriveAI15/5/202617/6/2026
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.
AnalizadaMedia (6)0.37%—Mongodb PHP Driver14/5/202624/9/2026
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
AplazadaAlta (8.7)0.63%—Quark DriveAI13/5/202614/7/2026
Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace…
AplazadaMedia (5.1)0.32%—Quark DriveAI13/5/202614/7/2026
Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update…
Pendiente de análisisMedia (5.6)0.18%💥 PoCNXP Moal.koAINXP Wi-fi DriverAI13/5/202617/6/2026
NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function.
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially…
Pendiente de análisisCrítica (9.3)0.13%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…
Pendiente de análisisMedia (6.9)0.10%—Intel NPU DriverAI12/5/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…