Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

4530 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.23%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receiver thread (which handles shell creation/destruction) and the telemetry sender thread (which polls…
AnalizadaMedia (6.5)0.29%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and WriteFile operations to proceed with invalid sessions or closed file descriptors. This enables an…
AnalizadaMedia (6.8)0.32%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVLink FTP implementation allows any MAVLink peer to read, write, create, delete, and rename arbitrary files on the flight controller filesystem without authentication. On…
ModificadaAlta (8)0.26%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message to force an unbounded stack allocation and copy, causing a stack…
ModificadaMedia (6.1)0.27%💥 PoCDronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN frames are processed. In deployments where tattu_can is enabled and running, a CAN-injection-capable attacker can trigger…
ModificadaAlta (8.1)0.31%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer without a bounds check. In deployments where crsf_rc is enabled on a CRSF serial port, an adjacent/raw-serial attacker can…
ModificadaMedia (6.8)0.28%—Dronecode PX4 Drone Autopilot16/3/202617/6/2026
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provided length without bounds. A malicious BST device can report an oversized dev_name_len, causing a stack overflow in the driver and crashing the task (or enabling code…
Pendiente de análisisAlta (7.7)0.49%—Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI16/3/202617/6/2026
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
Pendiente de análisisMedia (5.3)0.37%—Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI16/3/202617/6/2026
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.
AplazadaMedia (5.3)0.29%—Swit WP Sessions Time Monitoring Full AutomaticAI13/3/202617/6/2026
Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3.
AnalizadaMedia (5.4)0.34%—Inductiveautomation Ignition12/3/202617/6/2026
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
AplazadaBaja (2.1)0.39%—Autohomecorp FrostmourneAIOracle Nashorn Javascript EngineAI12/3/202617/6/2026
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has…
AnalizadaAlta (8.1)0.31%—Dronecode PX4 Drone Autopilot10/3/202617/6/2026
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing,…
AnalizadaAlta (8.1)0.30%—Dronecode PX4 Drone Autopilot10/3/202617/6/2026
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the system lacks a throttle threshold…
AnalizadaCrítica (9.3)0.98%—Bukts BUK Ts-g GAS Station Automation System10/3/202610/8/2026
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data…
AplazadaMedia (6.4)0.34%💥 PoCNextscripts Social Networks Auto PosterAI10/3/202617/6/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for…
AnalizadaAlta (7.2)0.24%—Schneider-electric Ecostruxure Automation Expert10/3/202623/6/2026
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent…
AnalizadaAlta (7.8)0.31%—Microsoft Azure Automation Hybrid Worker Windows Extension10/3/202617/6/2026
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.8)0.58%—Nextscripts Social-networks-auto-poster-facebook-twitter-gAI5/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
AplazadaAlta (7.1)0.26%—Kamleshyadav WP Bakery Autoresponder AddonAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Stored XSS.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.
AplazadaMedia (6.5)0.34%—Kamleshyadav WP Bakery Autoresponder AddonAI5/3/202617/6/2026
Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.
AnalizadaAlta (7.8)0.22%💥 PoCApp-auto-patch4/3/202617/6/2026
Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
AplazadaAlta (7.2)0.67%—Uncannyowl Uncanny AutomatorAI3/3/202617/6/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access…
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaAlta (7.8)0.07%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1662/3/202617/6/2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.