Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Uc-http20/2/202417/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaMedia (5.9)0.81%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within…
ModificadaMedia (5.9)0.81%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within…
ModificadaCrítica (9.1)1.1%—Weston-embedded Uc-tcp-ip20/2/202417/6/2026
A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this…
ModificadaMedia (6)0.16%—AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600gt Firmware+12513/2/20242/9/2026
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
ModificadaAlta (7.8)0.18%—AMD Ryzen Embedded 5950e FirmwareAMD Ryzen Embedded 5900e FirmwareAMD Ryzen Embedded 5800e FirmwareAMD Ryzen Embedded 5600e Firmware+613/2/202417/6/2026
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.
ModificadaMedia (5.4)0.74%💥 PoCDandulaney Dan's Embedder FOR Google Calendar5/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.
ModificadaMedia (5.4)0.29%—Epiph Embed Privacy1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epiphyt Embed Privacy allows Stored XSS.This issue affects Embed Privacy: from n/a through 1.8.0.
ModificadaMedia (5.4)0.33%—Takayukimiyauchi Oembed Gist1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi oEmbed Gist allows Stored XSS.This issue affects oEmbed Gist: from n/a through 4.9.1.
ModificadaAlta (7.5)1.1%—ARM Mbed TLSTrustedfirmware Mbed TLS31/1/202417/6/2026
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
ModificadaMedia (5.5)0.31%—ARM Mbed TLSTrustedfirmware Mbed TLS31/1/202417/6/2026
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in…
ModificadaAlta (7.5)0.69%—Trustedfirmware Mbed TLS21/1/202417/6/2026
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
ModificadaAlta (7.5)0.46%—ARM Mbed TLS21/1/202417/6/2026
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
ModificadaAlta (7.5)0.78%—Embedchain21/1/202417/6/2026
The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.
ModificadaCrítica (9.8)1.1%—Embedchain21/1/202417/6/2026
The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.
ModificadaCrítica (9.6)0.55%—Chromiumembedded Chromium Embedded Framework13/1/202417/6/2026
Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e.
ModificadaCrítica (9.6)0.70%—Chromiumembedded Chromium Embedded Framework12/1/202417/6/2026
CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit…
ModificadaMedia (5.4)0.42%—Wpdeveloper Embedpress3/1/202417/6/2026
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization and…
ModificadaMedia (5.4)0.31%—Elearningfreak Insert OR Embed Articulate Content21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.6)0.79%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+414/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client.…
ModificadaAlta (8.8)1.7%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+314/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server…
ModificadaAlta (8.8)1.7%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+314/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server…
ModificadaMedia (6.1)0.47%—Wpdeveloper Embedpress11/12/202317/6/2026
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.46%—Wpdeveloper Embedpress11/12/202317/6/2026
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Orbitaley — Vulnerabilidades