Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1271 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.32% | — | Mongodb C Driver | 13/4/2026 | 17/6/2026 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Dynabook Bluetooth Acpi DriversAI | 13/4/2026 | 17/6/2026 | Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values. | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | Opentext IDM Scim DriverAI | 27/3/2026 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1.0.1.0300 and… | |
| Pendiente de análisis | Media (6.5) | 0.81% | — | Kubernetes CSI Driver FOR NFSAI | 20/3/2026 | 17/6/2026 | A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During… | |
| Analizada | Baja (2) | 0.24% | — | Mongodb C Driver | 17/3/2026 | 17/6/2026 | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Spinnaker ClouddriverAISpinnaker OrcaAI | 17/3/2026 | 17/6/2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.… | |
| Pendiente de análisis | Media (5.4) | 0.13% | — | Asus ROG Peripheral DriverAI | 12/3/2026 | 17/9/2026 | An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is… | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information… | |
| Aplazada | Alta (7.8) | 0.13% | — | Epson Printer Driver InstallerAI | 19/2/2026 | 17/6/2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing… | |
| Aplazada | Media (4.6) | 0.17% | — | RAS TA DriverAI | 12/2/2026 | 17/6/2026 | Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition. | |
| Aplazada | Media (6.9) | 0.14% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service. | |
| Aplazada | Alta (8.8) | 0.17% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.16% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service | |
| Aplazada | Media (6.9) | 0.24% | — | Mongodb Mongo-go-driverAI | 10/2/2026 | 17/6/2026 | The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be… | |
| Aplazada | Media (5.7) | 0.09% | — | Intel NPU DriversAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Aplazada | Baja (2) | 0.15% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access… | |
| Analizada | Baja (2) | 0.09% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Alta (7.8) | 0.17% | — | Avanquest PC Helpsoft Driver Updater | 3/2/2026 | 17/6/2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | |
| Aplazada | Media (5.5) | 0.13% | — | Nvidia HD Audio DriverAI | 28/1/2026 | 17/6/2026 | NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful exploit of this vulnerability might lead to a denial of service. | |
| Aplazada | Alta (7.8) | 0.21% | — | Nvidia Display Driver FOR LinuxAI | 28/1/2026 | 17/6/2026 | NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wraparound. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure. | |
| Aplazada | Alta (7.8) | 0.21% | — | Nvidia GPU Display DriverAI | 28/1/2026 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure. |