Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.40% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions. | |
| Modificada | Alta (7.8) | 0.69% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions. | |
| Modificada | Alta (7.8) | 0.69% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions.… | |
| Modificada | Media (6.8) | 0.47% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel. See NCC-NCC-019 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later… | |
| Modificada | Crítica (9.8) | 2.3% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions. version… | |
| Modificada | Alta (7.8) | 0.41% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions. | |
| Modificada | Alta (7.8) | 0.45% | — | Zephyrproject Zephyr | 11/5/2020 | 17/6/2026 | USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a malicious USB host to exploit the buffer overflow. See NCC-ZEP-002 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later… | |
| Modificada | Media (5.5) | 0.27% | — | Jenkins Zephyr FOR Jira Test Management | 9/3/2020 | 17/6/2026 | Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system. | |
| Modificada | Media (5.5) | 0.33% | — | Jenkins Zephyr Enterprise Test Management | 9/3/2020 | 17/6/2026 | Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system. | |
| Modificada | Media (6.8) | 0.38% | — | Asus ROG Zephyrus M Gm501gs Firmware | 20/10/2019 | 17/6/2026 | The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in which booting from a USB device is prohibited. Attackers who have physical laptop access can exhaust the main battery to… | |
| Modificada | Alta (7.8) | 0.57% | — | Zephyrproject Zephyr | 29/8/2019 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all. | |
| Modificada | Alta (7.8) | 1.1% | — | Zephyrproject Zephyr | 29/8/2019 | 17/6/2026 | Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zephyrproject Zephyr | 12/4/2019 | 17/6/2026 | A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Zephyr Enterprise Test Management | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Zephyr Enterprise Test Management | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zephyrproject Zephyr | 6/9/2018 | 17/6/2026 | zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010). This attack appear to be exploitable via a malicious application call the vulnerable kernel APIs (system sys_ring_buf_get() and… | |
| Modificada | Media (6.4) | 15% | — | Zephyrsoft Toolbox Address Book Continued | 27/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was… | |
| Modificada | Media (6.4) | 1.1% | — | Zephyrsoft Toolbox Address Book Continued | 27/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third… |