Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.08% | — | Intel NPU DriverAI | 12/5/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Windows Display Virtualization DriverAI | 12/5/2026 | 17/6/2026 | Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via… | |
| Pendiente de análisis | Crítica (9.2) | 0.71% | — | Amazon Redshift Jdbc DriverAI | 8/5/2026 | 17/6/2026 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a… | |
| Aplazada | Crítica (9.6) | 0.40% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Media (6.5) | 0.17% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.3) | 0.22% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 5/10/2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2. | |
| Analizada | Alta (8.6) | 0.18% | — | Mongodb C Driver | 6/5/2026 | 18/6/2026 | The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI. | |
| Modificada | Alta (7.5) | 4.1% | — | Postgresql Jdbc Driver | 29/4/2026 | 11/9/2026 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough… | |
| Aplazada | Media (6.8) | 0.13% | — | Drive Power ManagerAI | 26/4/2026 | 17/6/2026 | Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition. | |
| Analizada | Media (6.9) | 0.75% | — | Amazon EFS CSI Driver | 17/4/2026 | 17/6/2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Media (5.4) | 0.14% | 💥 PoC | Asus DriverhubAI | 16/4/2026 | 17/9/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to… | |
| Analizada | Media (5.3) | 0.32% | — | Mongodb C Driver | 13/4/2026 | 17/6/2026 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Dynabook Bluetooth Acpi DriversAI | 13/4/2026 | 17/6/2026 | Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values. | |
| Analizada | Media (6.9) | 0.21% | — | Southrivertech Webdrive | 30/3/2026 | 7/10/2026 | WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer-overflow payload of 5000 bytes in the username parameter and trigger a… | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | Opentext IDM Scim DriverAI | 27/3/2026 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1.0.1.0300 and… | |
| Aplazada | Alta (8.1) | 0.56% | — | Mikado-themes LuxedriveAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes LuxeDrive luxedrive allows PHP Local File Inclusion.This issue affects LuxeDrive: from n/a through <= 1.0. | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | IdriveAI | 24/3/2026 | 21/7/2026 | In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged… | |
| Pendiente de análisis | Media (6.5) | 0.81% | — | Kubernetes CSI Driver FOR NFSAI | 20/3/2026 | 17/6/2026 | A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During… | |
| Analizada | Baja (2) | 0.24% | — | Mongodb C Driver | 17/3/2026 | 17/6/2026 | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Spinnaker ClouddriverAISpinnaker OrcaAI | 17/3/2026 | 17/6/2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.… | |
| Pendiente de análisis | Media (5.4) | 0.13% | — | Asus ROG Peripheral DriverAI | 12/3/2026 | 17/9/2026 | An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is… | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information… |