Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.13% | — | Epson Printer Driver InstallerAI | 19/2/2026 | 17/6/2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing… | |
| Aplazada | Media (4.6) | 0.17% | — | RAS TA DriverAI | 12/2/2026 | 17/6/2026 | Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition. | |
| Aplazada | Media (6.9) | 0.14% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service. | |
| Aplazada | Alta (8.8) | 0.17% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.16% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service | |
| Aplazada | Media (6.9) | 0.24% | — | Mongodb Mongo-go-driverAI | 10/2/2026 | 17/6/2026 | The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be… | |
| Aplazada | Media (5.7) | 0.09% | — | Intel NPU DriversAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Aplazada | Baja (2) | 0.15% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access… | |
| Analizada | Baja (2) | 0.09% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Alta (7.8) | 0.17% | — | Avanquest PC Helpsoft Driver Updater | 3/2/2026 | 17/6/2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | |
| Aplazada | Media (5.5) | 0.13% | — | Nvidia HD Audio DriverAI | 28/1/2026 | 17/6/2026 | NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful exploit of this vulnerability might lead to a denial of service. | |
| Aplazada | Alta (7.8) | 0.21% | — | Nvidia Display Driver FOR LinuxAI | 28/1/2026 | 17/6/2026 | NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wraparound. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure. | |
| Aplazada | Alta (7.8) | 0.21% | — | Nvidia GPU Display DriverAI | 28/1/2026 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure. | |
| Aplazada | Alta (7.8) | 0.20% | — | Nvidia Display Driver FOR WindowsAI | 28/1/2026 | 17/6/2026 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Aplazada | Alta (8.5) | 0.20% | — | Wondershare Driver Install ServiceAI | 27/1/2026 | 17/6/2026 | Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to… | |
| Aplazada | Media (5.4) | 0.26% | — | Softlabbd Integrate Google DriveAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.5.6. | |
| Modificada | Alta (7.3) | 0.16% | 💥 PoC | Ludashi Driver | 15/1/2026 | 5/7/2026 | A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlled structures containing the lower 4GB of physical addresses. The handler maps… | |
| Analizada | Media (6.4) | 0.16% | — | Espressif USB Host HID Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously,… | |
| Analizada | Media (6.8) | 0.21% | — | Espressif USB Host HID Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees and reallocates hid_device->ctrl_xfer when an oversized descriptor is requested but continues to use the stale local pointer, leading to an immediate use-after-free when… | |
| Analizada | Media (6.8) | 0.24% | — | Espressif USB Host UVC Class Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in the esp-usb UVC host implementation allows a malicious USB Video Class (UVC) device to trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor… | |
| Aplazada | Media (5.1) | 0.26% | — | Legrand Bticino Driver Manager F454AI | 24/12/2025 | 17/6/2026 | Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET… | |
| Aplazada | Alta (8.5) | 0.14% | — | USB Flash Drives ControlAI | 17/12/2025 | 17/6/2026 | USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate… |