Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.29% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android | 1/7/2024 | 17/6/2026 | In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424. | |
| Analizada | Media (5.5) | 0.42% | — | Linuxfoundation Harbor | 11/6/2024 | 17/6/2026 | SQL-Injection in Harbor allows priviledge users to leak the task IDs | |
| Analizada | Media (6.1) | 0.36% | — | Linuxfoundation Harbor | 10/6/2024 | 17/6/2026 | Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site. | |
| Modificada | Alta (8.8) | 1.2% | — | Linuxfoundation Onnx | 6/6/2024 | 17/6/2026 | A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to… | |
| Aplazada | Media (5.3) | 0.44% | — | Linuxfoundation DaprAI | 23/5/2024 | 17/6/2026 | Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of the app token of the invoked app. This causes of a leak of the application token of the invoker app to the invoked app when using Dapr as a gRPC proxy for remote… | |
| Aplazada | Media (4.9) | 0.75% | — | Linuxfoundation VitessAI | 8/5/2024 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7. | |
| Analizada | Media (5.3) | 0.08% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 6/5/2024 | 17/6/2026 | In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514. | |
| Analizada | Media (5.3) | 0.16% | — | Linuxfoundation Ric-app-kpimon-go | 30/4/2024 | 17/6/2026 | O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message. | |
| Analizada | Media (5.5) | 0.21% | — | Linuxfoundation Onos-lib-go | 30/4/2024 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString. | |
| Analizada | Alta (8.1) | 0.53% | — | Linuxfoundation Onos-lib-go | 30/4/2024 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits. | |
| Analizada | Media (6.5) | 0.42% | — | Linuxfoundation Onos-ric-sdk-go | 30/4/2024 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function implementation for the subscribed indication stream). | |
| Analizada | Media (6.5) | 0.43% | — | Linuxfoundation Onos-kpimon | 30/4/2024 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package. | |
| Analizada | Alta (8.1) | 0.88% | — | Linuxfoundation Onos-kpimon | 30/4/2024 | 17/6/2026 | Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function. | |
| Analizada | Media (5.5) | 0.38% | — | Linuxfoundation Pytorch | 19/4/2024 | 17/6/2026 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. | |
| Analizada | Alta (7.8) | 0.27% | — | Linuxfoundation Pytorch | 17/4/2024 | 17/6/2026 | Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp. | |
| Analizada | Media (4) | 0.22% | — | Linuxfoundation Pytorch | 17/4/2024 | 17/6/2026 | PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Media (6.3) | 0.08% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle Android | 1/4/2024 | 17/6/2026 | In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012. | |
| Analizada | Media (6.6) | 0.27% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200. | |
| Analizada | Alta (8.4) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761. | |
| Analizada | Baja (2.3) | 0.08% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765. | |
| Analizada | Alta (8.8) | 0.18% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidLinux Kernel+1 | 1/4/2024 | 17/6/2026 | In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX… | |
| Analizada | Media (6) | 0.61% | — | Linuxfoundation Fluid | 15/3/2024 | 17/6/2026 | Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD… |