Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.22% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. | |
| Analizada | Alta (8.8) | 0.19% | — | Nvidia GPU Display Driver | 26/5/2026 | 20/7/2026 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. | |
| Analizada | Media (6.5) | 0.13% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Media (6) | 0.18% | — | Nvidia GPU Display Driver | 26/5/2026 | 24/7/2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Analizada | Media (6) | 0.30% | — | Mongodb C Driver | 20/5/2026 | 24/9/2026 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an… | |
| Pendiente de análisis | Crítica (9.3) | 0.80% | 💥 PoC | Amazon Redshift-python-driverAI | 18/5/2026 | 23/7/2026 | Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14. | |
| Modificada | Crítica (9.8) | 3.3% | — | Openjsf Webdriverio | 18/5/2026 | 24/7/2026 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and… | |
| Aplazada | Alta (8.7) | 0.64% | — | Google Drive FOR WordpressAI | 17/5/2026 | 17/6/2026 | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name… | |
| Aplazada | Alta (8.5) | 0.12% | — | Privacy DriveAI | 16/5/2026 | 17/6/2026 | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with LocalSystem… | |
| Pendiente de análisis | Baja (2) | 0.07% | — | AMD Mxgpu-virtualization DriverAI | 15/5/2026 | 17/6/2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system… | |
| Pendiente de análisis | Baja (1.8) | 0.10% | — | TEE SOC DriverAI | 15/5/2026 | 17/6/2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | AMD Sensor Fusion HUB DriverAI | 15/5/2026 | 17/6/2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash | |
| Pendiente de análisis | Alta (8.6) | 0.11% | — | AMD Raid DriverAI | 15/5/2026 | 17/6/2026 | Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Chipset DriverAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash. | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | AMD OverdriveAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality. | |
| Analizada | Media (6) | 0.37% | — | Mongodb PHP Driver | 14/5/2026 | 24/9/2026 | Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server. | |
| Aplazada | Alta (8.7) | 0.63% | — | Quark DriveAI | 13/5/2026 | 14/7/2026 | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace… | |
| Aplazada | Media (5.1) | 0.32% | — | Quark DriveAI | 13/5/2026 | 14/7/2026 | Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update… | |
| Pendiente de análisis | Media (5.6) | 0.18% | 💥 PoC | NXP Moal.koAINXP Wi-fi DriverAI | 13/5/2026 | 17/6/2026 | NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function. | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | Intel NPU DriverAI | 12/5/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur… |