Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.53%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.53%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaAlta (7.5)0.48%—Silabs Gecko Software Development KIT18/5/202317/6/2026
Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
ModificadaCrítica (9.6)23%—Expo Software Development KIT24/4/202317/6/2026
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various…
ModificadaAlta (7.8)0.64%—Autodesk FBX Software Development KIT17/4/202317/6/2026
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
ModificadaAlta (7.8)0.53%—Autodesk FBX Software Development KIT17/4/202317/6/2026
A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
ModificadaAlta (7.8)0.49%—Autodesk FBX Software Development KIT17/4/202317/6/2026
An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure.
ModificadaMedia (6.5)0.31%—Silabs Gecko Software Development KIT28/3/202317/6/2026
An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.
ModificadaMedia (6.5)0.65%—Sentry Software Development KIT22/3/202317/6/2026
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies values, including the session cookie to Sentry. These sensitive cookies could then…
ModificadaMedia (5.3)0.44%—Silabs Wi-sun Software Development KIT21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.
ModificadaMedia (5.5)0.23%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.20%—Intel Media Software Development KIT16/2/202317/6/2026
NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Improper buffer restrictions in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.18%—Intel Fpga Software Development KITIntel Quartus Prime16/2/202317/6/2026
Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Fpga Software Development KITIntel Quartus Prime16/2/202317/6/2026
Improper access control in the Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)0.32%—Splunk Add-on BuilderSplunk Cloudconnect Software Development KIT14/2/202317/6/2026
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write…
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability…