Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.23% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receiver thread (which handles shell creation/destruction) and the telemetry sender thread (which polls… | |
| Analizada | Media (6.5) | 0.29% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and WriteFile operations to proceed with invalid sessions or closed file descriptors. This enables an… | |
| Analizada | Media (6.8) | 0.32% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVLink FTP implementation allows any MAVLink peer to read, write, create, delete, and rename arbitrary files on the flight controller filesystem without authentication. On… | |
| Modificada | Alta (8) | 0.26% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message to force an unbounded stack allocation and copy, causing a stack… | |
| Modificada | Media (6.1) | 0.27% | 💥 PoC | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN frames are processed. In deployments where tattu_can is enabled and running, a CAN-injection-capable attacker can trigger… | |
| Modificada | Alta (8.1) | 0.31% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer without a bounds check. In deployments where crsf_rc is enabled on a CRSF serial port, an adjacent/raw-serial attacker can… | |
| Modificada | Media (6.8) | 0.28% | — | Dronecode PX4 Drone Autopilot | 16/3/2026 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provided length without bounds. A malicious BST device can report an oversized dev_name_len, causing a stack overflow in the driver and crashing the task (or enabling code… | |
| Pendiente de análisis | Alta (7.7) | 0.49% | — | Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI | 16/3/2026 | 17/6/2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42 | |
| Pendiente de análisis | Media (5.3) | 0.37% | — | Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI | 16/3/2026 | 17/6/2026 | Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03. | |
| Aplazada | Media (5.3) | 0.29% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3. | |
| Analizada | Media (5.4) | 0.34% | — | Inductiveautomation Ignition | 12/3/2026 | 17/6/2026 | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code. | |
| Aplazada | Baja (2.1) | 0.39% | — | Autohomecorp FrostmourneAIOracle Nashorn Javascript EngineAI | 12/3/2026 | 17/6/2026 | A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has… | |
| Analizada | Alta (8.1) | 0.31% | — | Dronecode PX4 Drone Autopilot | 10/3/2026 | 17/6/2026 | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing,… | |
| Analizada | Alta (8.1) | 0.30% | — | Dronecode PX4 Drone Autopilot | 10/3/2026 | 17/6/2026 | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the system lacks a throttle threshold… | |
| Analizada | Crítica (9.3) | 0.98% | — | Bukts BUK Ts-g GAS Station Automation System | 10/3/2026 | 10/8/2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data… | |
| Aplazada | Media (6.4) | 0.34% | 💥 PoC | Nextscripts Social Networks Auto PosterAI | 10/3/2026 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.24% | — | Schneider-electric Ecostruxure Automation Expert | 10/3/2026 | 23/6/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft Azure Automation Hybrid Worker Windows Extension | 10/3/2026 | 17/6/2026 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.8) | 0.58% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Aplazada | Alta (7.1) | 0.26% | — | Kamleshyadav WP Bakery Autoresponder AddonAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Stored XSS.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.5) | 0.34% | — | Kamleshyadav WP Bakery Autoresponder AddonAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6. | |
| Analizada | Alta (7.8) | 0.22% | 💥 PoC | App-auto-patch | 4/3/2026 | 17/6/2026 | Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. | |
| Aplazada | Alta (7.2) | 0.67% | — | Uncannyowl Uncanny AutomatorAI | 3/3/2026 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. |