Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1540 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.13%—Epson Printer Driver InstallerAI19/2/202617/6/2026
The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing…
AplazadaMedia (4.6)0.17%—RAS TA DriverAI12/2/202617/6/2026
Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.
AplazadaMedia (6.9)0.14%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.
AplazadaAlta (8.8)0.17%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.
AplazadaMedia (5.5)0.16%—AMD Graphics DriverAI11/2/202617/6/2026
The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service
AplazadaMedia (6.9)0.24%—Mongodb Mongo-go-driverAI10/2/202617/6/2026
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be…
AplazadaMedia (5.7)0.09%—Intel NPU DriversAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when…
AplazadaBaja (2)0.15%—Intel NPU DriverAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access…
AnalizadaBaja (2)0.09%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AplazadaMedia (6.8)0.10%—Intel NPU DriverAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
AnalizadaMedia (5.4)0.12%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via…
AnalizadaMedia (5.4)0.12%—Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel10/2/202617/6/2026
Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may…
AnalizadaAlta (7.8)0.17%—Avanquest PC Helpsoft Driver Updater3/2/202617/6/2026
Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.
AplazadaMedia (5.5)0.13%—Nvidia HD Audio DriverAI28/1/202617/6/2026
NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful exploit of this vulnerability might lead to a denial of service.
AplazadaAlta (7.8)0.21%—Nvidia Display Driver FOR LinuxAI28/1/202617/6/2026
NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wraparound. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
AplazadaAlta (7.8)0.21%—Nvidia GPU Display DriverAI28/1/202617/6/2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
AplazadaAlta (7.8)0.20%—Nvidia Display Driver FOR WindowsAI28/1/202617/6/2026
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
AplazadaAlta (8.5)0.20%—Wondershare Driver Install ServiceAI27/1/202617/6/2026
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to…
AplazadaMedia (5.4)0.26%—Softlabbd Integrate Google DriveAI23/1/202617/6/2026
Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.5.6.
ModificadaAlta (7.3)0.16%💥 PoCLudashi Driver15/1/20265/7/2026
A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlled structures containing the lower 4GB of physical addresses. The handler maps…
AnalizadaMedia (6.4)0.16%—Espressif USB Host HID Driver12/1/202617/6/2026
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously,…
AnalizadaMedia (6.8)0.21%—Espressif USB Host HID Driver12/1/202617/6/2026
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees and reallocates hid_device->ctrl_xfer when an oversized descriptor is requested but continues to use the stale local pointer, leading to an immediate use-after-free when…
AnalizadaMedia (6.8)0.24%—Espressif USB Host UVC Class Driver12/1/202617/6/2026
Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in the esp-usb UVC host implementation allows a malicious USB Video Class (UVC) device to trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor…
AplazadaMedia (5.1)0.26%—Legrand Bticino Driver Manager F454AI24/12/202517/6/2026
Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET…
AplazadaAlta (8.5)0.14%—USB Flash Drives ControlAI17/12/202517/6/2026
USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate…
Orbitaley — Vulnerabilidades