Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1271 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.32%—Mongodb C Driver13/4/202617/6/2026
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions…
Pendiente de análisisAlta (8.4)0.21%—Dynabook Bluetooth Acpi DriversAI13/4/202617/6/2026
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.
Pendiente de análisisAlta (7.3)0.11%—Opentext IDM Scim DriverAI27/3/202617/6/2026
Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1.0.1.0300 and…
Pendiente de análisisMedia (6.5)0.81%—Kubernetes CSI Driver FOR NFSAI20/3/202617/6/2026
A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During…
AnalizadaBaja (2)0.24%—Mongodb C Driver17/3/202617/6/2026
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
AplazadaCrítica (9.1)0.40%—Spinnaker ClouddriverAISpinnaker OrcaAI17/3/202617/6/2026
### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.…
Pendiente de análisisMedia (5.4)0.13%—Asus ROG Peripheral DriverAI12/3/202617/9/2026
An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is…
Pendiente de análisisMedia (6.9)0.11%—Asus Business System Control Interface DriverAI12/3/202617/6/2026
An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for…
Pendiente de análisisMedia (6.8)0.10%—Asus Business System Control Interface DriverAI12/3/202617/6/2026
An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information…
AplazadaAlta (7.8)0.13%—Epson Printer Driver InstallerAI19/2/202617/6/2026
The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing…
AplazadaMedia (4.6)0.17%—RAS TA DriverAI12/2/202617/6/2026
Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.
AplazadaMedia (6.9)0.14%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.
AplazadaAlta (8.8)0.17%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.
AplazadaMedia (5.5)0.16%—AMD Graphics DriverAI11/2/202617/6/2026
The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service
AplazadaMedia (6.9)0.24%—Mongodb Mongo-go-driverAI10/2/202617/6/2026
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be…
AplazadaMedia (5.7)0.09%—Intel NPU DriversAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when…
AplazadaBaja (2)0.15%—Intel NPU DriverAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access…
AnalizadaBaja (2)0.09%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AplazadaMedia (6.8)0.10%—Intel NPU DriverAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
AnalizadaMedia (5.4)0.12%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via…
AnalizadaMedia (5.4)0.12%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may…
AnalizadaAlta (7.8)0.17%—Avanquest PC Helpsoft Driver Updater3/2/202617/6/2026
Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.
AplazadaMedia (5.5)0.13%—Nvidia HD Audio DriverAI28/1/202617/6/2026
NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful exploit of this vulnerability might lead to a denial of service.
AplazadaAlta (7.8)0.21%—Nvidia Display Driver FOR LinuxAI28/1/202617/6/2026
NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wraparound. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
AplazadaAlta (7.8)0.21%—Nvidia GPU Display DriverAI28/1/202617/6/2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
Orbitaley — Vulnerabilidades