Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.15%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID:…
AnalizadaMedia (4.4)0.14%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
AnalizadaMedia (5.5)0.11%—Mediatek Mt6990 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 Firmware+23/8/202619/8/2026
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735,…
AnalizadaMedia (5.5)0.15%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 FirmwareMediatek Mt6988 Firmware+13/8/202619/8/2026
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue…
AnalizadaMedia (4.4)0.14%—Mediatek Mt6813 FirmwareMediatek Mt6982vb FirmwareMediatek Mt6986 FirmwareMediatek Mt6986d Firmware+13/8/202619/8/2026
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
AnalizadaMedia (4.4)0.16%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.
AnalizadaMedia (4.4)0.16%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.
AnalizadaMedia (6.7)0.17%—Mediatek Mt8910 FirmwareMediatek Mt2718 FirmwareMediatek Mt6878 FirmwareMediatek Mt6895 Firmware+73/8/202619/8/2026
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
AnalizadaMedia (6)0.16%—Mediatek Mt6993 Firmware3/8/202619/8/2026
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.
AnalizadaMedia (4.4)0.16%—Mediatek Mt8799 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+353/8/202619/8/2026
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
AnalizadaAlta (7.7)0.17%—Mediatek Mt8893 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+313/8/202619/8/2026
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
AnalizadaMedia (6.5)0.30%—Mediatek Mt8532 FirmwareMediatek Mt7902 FirmwareMediatek Mt7921 FirmwareMediatek Mt7922 Firmware+13/8/202619/8/2026
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
AnalizadaMedia (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+103/8/202619/8/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
AnalizadaMedia (5.5)0.14%—Mediatek Mt6880 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 Firmware+33/8/202619/8/2026
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For…
AnalizadaAlta (7.5)0.71%—Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+153/8/202619/8/2026
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071;…
AnalizadaMedia (5.5)0.14%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 FirmwareMediatek Mt6890 Firmware+23/8/202620/8/2026
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735,…
AnalizadaMedia (6)0.17%—Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8188 Firmware+63/8/202619/8/2026
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.
AnalizadaMedia (5.5)0.15%—Mediatek Mt6988 FirmwareMediatek Mt6813 FirmwareMediatek Mt6986 Firmware3/8/202619/8/2026
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.
AnalizadaMedia (6)0.17%—Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+133/8/202619/8/2026
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.
AnalizadaMedia (6)0.13%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.
AnalizadaMedia (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8910 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+133/8/202619/8/2026
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.
AplazadaMedia (4.6)0.23%—Mediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AIMediatek Mt6988AI+43/8/202628/8/2026
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890,…
AplazadaMedia (6.1)0.17%—Mediatek Mt2737AIMediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AI3/8/202628/8/2026
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For…
AplazadaMedia (5.4)0.13%—Najeebmedia Frontend File ManagerAI2/8/202626/8/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,…
AnalizadaAlta (8.2)0.46%—Ueberauth Guardian1/8/20266/8/2026
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and…