Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.96%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
ModificadaMedia (6.5)0.83%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
ModificadaAlta (7.5)5.1%—Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+3126/2/202217/6/2026
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
ModificadaMedia (4.7)0.22%—Backblaze B2 Python Software Development KIT23/2/202217/6/2026
b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of…
ModificadaMedia (6.5)1.00%—Dart Software Development KIT18/2/202217/6/2026
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it…
ModificadaMedia (5.3)1.4%—TI Simplelink Cc32xx Software Development KITTI Cc3100 FirmwareTI Cc3200 Firmware16/2/202217/6/2026
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaMedia (4.6)0.25%—Intel Active Management Technology Software Development KITIntel Setup AND Configuration SoftwareIntel Management Engine Bios ExtensionIntel Core I3 Firmware+1769/2/202217/6/2026
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical…
ModificadaCrítica (9.8)1.5%—Mediatek Linkit Software Development KIT24/1/202217/6/2026
In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.
ModificadaAlta (7.8)1.1%—Opendesign Drawings Software Development KIT15/1/202217/6/2026
Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaBaja (3.5)0.60%—Dart Software Development KIT5/1/202217/6/2026
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
ModificadaCrítica (9.8)2.8%—Microsoft BOT Framework Software Development KIT15/12/202117/6/2026
Bot Framework SDK Remote Code Execution Vulnerability
ModificadaAlta (8.8)0.94%—Dart Software Development KIT9/12/202117/6/2026
When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past…
ModificadaAlta (7.5)1.4%—Yubico Yubihsm 2 Software Development KIT8/12/202117/6/2026
The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and some data operations received from a YubiHSM 2 device.
ModificadaAlta (7.2)0.64%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA has been “overridden”. TLS handshakes will thus succeed if the peer can be verified…
ModificadaAlta (8.8)0.39%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with…
ModificadaAlta (8.8)0.39%—Amazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.3) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust…
ModificadaAlta (8.8)0.41%—Amazon WEB Services Aws-c-ioAmazon WEB Services Internet OF Things Device Software Development KIT V223/11/202117/6/2026
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust…
ModificadaMedia (5.7)0.32%💥 PoCEdgexfoundry APP Service ConfigurableEdgexfoundry Application Functions Software Development KITEdgexfoundry Edgex Foundry19/11/202117/6/2026
Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/transforming/exporting data out of the EdgeX IoT platform. In affected versions broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to…
ModificadaAlta (7.8)1.7%—Opendesign Drawings Software Development KIT14/11/202117/6/2026
An Out-of-Bounds Read vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid dash counter in line types) can trigger a read past the end of an allocated buffer. An attacker…
ModificadaAlta (7.8)1.7%—Opendesign Drawings Software Development KIT14/11/202117/6/2026
An Out-of-Bounds Write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN files. Crafted data in a DGN file and lack of proper validation of input data can trigger a write operation past the end of an allocated…
ModificadaAlta (7.8)1.7%—Opendesign Drawings Software Development KITSiemens Jt2goSiemens Solid EdgeSiemens Teamcenter Visualization14/11/202117/6/2026
An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF and DWG files. Crafted data in a DXF or DWG file (an invalid number of properties) can trigger a write operation past the end of an…
ModificadaAlta (7.8)1.9%—Opendesign Drawings Software Development KIT14/11/202117/6/2026
A stack-based buffer overflow vulnerability exists in the DWF file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of proper validation of the length of user-supplied data before copying it to a stack-based buffer. An attacker can leverage this vulnerability to…
ModificadaAlta (7.8)1.3%—Opendesign ODA PRC Software Development KIT14/11/202117/6/2026
An out-of-bounds write vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the…
ModificadaAlta (7.8)0.84%—Opendesign ODA PRC Software Development KIT14/11/202117/6/2026
An out-of-bounds read vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the…