Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware | 3/8/2026 | 19/8/2026 | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID:… | |
| Analizada | Media (4.4) | 0.14% | — | Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware | 3/8/2026 | 19/8/2026 | In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575. | |
| Analizada | Media (5.5) | 0.11% | — | Mediatek Mt6990 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 Firmware+2 | 3/8/2026 | 19/8/2026 | In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735,… | |
| Analizada | Media (5.5) | 0.15% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 FirmwareMediatek Mt6988 Firmware+1 | 3/8/2026 | 19/8/2026 | In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue… | |
| Analizada | Media (4.4) | 0.14% | — | Mediatek Mt6813 FirmwareMediatek Mt6982vb FirmwareMediatek Mt6986 FirmwareMediatek Mt6986d Firmware+1 | 3/8/2026 | 19/8/2026 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669. | |
| Analizada | Media (4.4) | 0.16% | — | Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+13 | 3/8/2026 | 19/8/2026 | In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749. | |
| Analizada | Media (4.4) | 0.16% | — | Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+13 | 3/8/2026 | 19/8/2026 | In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | |
| Analizada | Media (6.7) | 0.17% | — | Mediatek Mt8910 FirmwareMediatek Mt2718 FirmwareMediatek Mt6878 FirmwareMediatek Mt6895 Firmware+7 | 3/8/2026 | 19/8/2026 | In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833. | |
| Analizada | Media (6) | 0.16% | — | Mediatek Mt6993 Firmware | 3/8/2026 | 19/8/2026 | In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931. | |
| Analizada | Media (4.4) | 0.16% | — | Mediatek Mt8799 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+35 | 3/8/2026 | 19/8/2026 | In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | |
| Analizada | Alta (7.7) | 0.17% | — | Mediatek Mt8893 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+31 | 3/8/2026 | 19/8/2026 | In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | |
| Analizada | Media (6.5) | 0.30% | — | Mediatek Mt8532 FirmwareMediatek Mt7902 FirmwareMediatek Mt7921 FirmwareMediatek Mt7922 Firmware+1 | 3/8/2026 | 19/8/2026 | In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824. | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+10 | 3/8/2026 | 19/8/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935. | |
| Analizada | Media (5.5) | 0.14% | — | Mediatek Mt6880 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 Firmware+3 | 3/8/2026 | 19/8/2026 | In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For… | |
| Analizada | Alta (7.5) | 0.71% | — | Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+15 | 3/8/2026 | 19/8/2026 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071;… | |
| Analizada | Media (5.5) | 0.14% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 FirmwareMediatek Mt6890 Firmware+2 | 3/8/2026 | 20/8/2026 | In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735,… | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8188 Firmware+6 | 3/8/2026 | 19/8/2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658. | |
| Analizada | Media (5.5) | 0.15% | — | Mediatek Mt6988 FirmwareMediatek Mt6813 FirmwareMediatek Mt6986 Firmware | 3/8/2026 | 19/8/2026 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660. | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+13 | 3/8/2026 | 19/8/2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | |
| Analizada | Media (6) | 0.13% | — | Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+13 | 3/8/2026 | 19/8/2026 | In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758. | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt6991 FirmwareMediatek Mt8910 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+13 | 3/8/2026 | 19/8/2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759. | |
| Aplazada | Media (4.6) | 0.23% | — | Mediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AIMediatek Mt6988AI+4 | 3/8/2026 | 28/8/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890,… | |
| Aplazada | Media (6.1) | 0.17% | — | Mediatek Mt2737AIMediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AI | 3/8/2026 | 28/8/2026 | In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For… | |
| Aplazada | Media (5.4) | 0.13% | — | Najeebmedia Frontend File ManagerAI | 2/8/2026 | 26/8/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,… | |
| Analizada | Alta (8.2) | 0.46% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and… |