Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Supported TAs` field. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet missing an expected `ENB_UE_S1AP_ID` field. | |
| Aplazada | Media (6.5) | 0.25% | — | Linuxfoundation MagmaAI | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Global eNB ID` field. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `TAI` field. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `EUTRAN_CGI` field. | |
| Modificada | Alta (7.5) | 0.77% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an oversized `Emergency Number List` Information… | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `eNB Configuration Transfer` packet missing its required `Target eNB ID` field. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `eNB_UE_S1AP_ID` field. | |
| Analizada | Alta (7.5) | 0.62% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone… | |
| Modificada | Media (6.5) | 0.40% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` packet missing an expected `eNB_UE_S1AP_ID` field. | |
| Modificada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` packet missing an expected `eNB_UE_S1AP_ID` field. | |
| Analizada | Media (6.5) | 0.25% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet missing an expected `MME_UE_S1AP_ID` field. | |
| Analizada | Media (6.5) | 0.38% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet missing an expected `ResetType` field. | |
| Analizada | Alta (7.5) | 0.73% | — | Linuxfoundation Magma | 21/1/2025 | 17/6/2026 | A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element. | |
| Analizada | Alta (7.5) | 0.32% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle Android | 6/1/2025 | 17/6/2026 | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598. | |
| Analizada | Media (4.4) | 0.09% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 6/1/2025 | 17/6/2026 | In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798. | |
| Analizada | Crítica (9.8) | 0.26% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle Android | 6/1/2025 | 17/6/2026 | In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796. | |
| Analizada | Alta (8.1) | 0.14% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 6/1/2025 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835. | |
| Analizada | Media (6.6) | 0.11% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 6/1/2025 | 17/6/2026 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040. | |
| Analizada | Media (6.6) | 0.11% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 6/1/2025 | 17/6/2026 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041. | |
| Analizada | Media (6.6) | 0.11% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 6/1/2025 | 17/6/2026 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069. | |
| Analizada | Media (6.7) | 0.08% | — | Linuxfoundation YoctoGoogle Android | 6/1/2025 | 17/6/2026 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020. | |
| Aplazada | Alta (7.5) | 0.44% | — | Linuxfoundation Open Cluster ManagementAI | 17/12/2024 | 17/6/2026 | A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which… | |
| Aplazada | Media (4.9) | 0.44% | — | Linuxfoundation VitessAI | 3/12/2024 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template… | |
| Analizada | Media (6.5) | 0.12% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 2/12/2024 | 17/6/2026 | In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600. |