Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.5%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.8%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
ModificadaMedia (6.1)0.63%—Sentry Software Development KIT10/11/202317/6/2026
sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. The problem has been fixed in version…
ModificadaMedia (6.5)0.29%—Silabs Gecko Software Development KIT29/9/202317/6/2026
Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.
ModificadaMedia (6.5)1.1%—Zoom Meeting Software Development KITZoom Virtual Desktop InfrastructureZoom12/9/202317/6/2026
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (5.3)0.83%—Pete4abw Lzma Software Development KIT17/8/202317/6/2026
lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
ModificadaAlta (7.8)0.14%—Intel Realsense Software Development KIT11/8/202317/6/2026
Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.16%—Intel Platform Service Record Software Development KIT11/8/202317/6/2026
Uncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.36%—Adobe XMP Toolkit Software Development KIT10/8/202317/6/2026
Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
ModificadaAlta (8.1)0.96%—Zoom Meeting Software Development KITZoom RoomsZoom8/8/202317/6/2026
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
ModificadaMedia (5.5)0.13%—Zoom Meeting Software Development KIT8/8/202317/6/2026
Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.
ModificadaAlta (7.5)1.6%—Zoom Meeting Software Development KITZoom Video Software Development KIT8/8/202317/6/2026
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.
ModificadaAlta (7.5)0.81%—Zoom Meeting Software Development KITZoom Video Software Development KIT8/8/202317/6/2026
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
ModificadaMedia (5.5)0.26%—Silabs Gecko Software Development KIT28/7/202317/6/2026
Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
ModificadaBaja (3.3)0.20%—Zoom Software Development KIT11/7/202317/6/2026
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable information disclosure via local access.
ModificadaAlta (7.5)0.53%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom+530/6/202317/6/2026
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
ModificadaAlta (8.8)0.42%—Silabs Unify Software Development KIT21/6/202317/6/2026
Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
ModificadaMedia (5.5)0.16%—Silabs Gecko Software Development KIT15/6/202317/6/2026
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.
ModificadaMedia (6.5)0.29%—Silabs Bluetooth LOW Energy Software Development KIT15/6/202317/6/2026
A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
ModificadaCrítica (9.8)0.76%—Silabs Gecko Software Development KIT15/6/202317/6/2026
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
ModificadaBaja (3.3)0.25%—Silabs Gecko Software Development KIT2/6/202317/6/2026
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.