Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.57% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This… | |
| Aplazada | Crítica (9.2) | 0.56% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including… | |
| Aplazada | Alta (8.5) | 0.45% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary… | |
| Aplazada | Media (6.9) | 0.57% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application details, potentially aiding in further attacks. This issue affects TeamDavid before Rollout 528. Starting… | |
| Aplazada | Alta (8.4) | 0.40% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place… | |
| Aplazada | Media (5.3) | 0.45% | — | Tobit Laboratories AG Teamdavid WebboxAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link,… | |
| Aplazada | Media (5.3) | 0.46% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e” (representing a dot), an attacker can manipulate the portion of the URL following the top-level domain… | |
| Aplazada | Alta (8.4) | 0.40% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid before Rollout 528. Starting with… | |
| Pendiente de análisis | Alta (7.7) | 0.51% | — | AMD Optional ToolsAI | 12/6/2026 | 17/6/2026 | The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution. | |
| Analizada | Media (6.8) | 0.14% | — | AMD Uprof | 9/6/2026 | 23/7/2026 | Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability. | |
| Analizada | Media (6.8) | 0.13% | — | AMD Uprof | 9/6/2026 | 23/7/2026 | Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service. | |
| Pendiente de análisis | Media (4) | 0.13% | — | AMD Secure ProcessorAIAMD IommuAI | 9/6/2026 | 23/7/2026 | Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAI | 1/6/2026 | 22/7/2026 | Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges. | |
| Modificada | Crítica (9.2) | 1.5% | — | AMD Aiter | 1/6/2026 | 22/7/2026 | AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no… | |
| Pendiente de análisis | Crítica (9.2) | 0.31% | — | AMD Device Metrics ExporterAI | 15/5/2026 | 17/6/2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability | |
| Pendiente de análisis | Alta (7.3) | 0.29% | — | AMD ZEN 2AI | 15/5/2026 | 10/9/2026 | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation. | |
| Pendiente de análisis | Baja (2) | 0.07% | — | AMD Mxgpu-virtualization DriverAI | 15/5/2026 | 17/6/2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system… | |
| Pendiente de análisis | Alta (7) | 0.08% | — | AMD Radeon RGB ToolAI | 15/5/2026 | 17/6/2026 | Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution. | |
| Analizada | Alta (7) | 0.12% | — | AMD Radeon SoftwareAMD Cleanup Utility | 15/5/2026 | 17/6/2026 | A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | AmdgvAI | 15/5/2026 | 17/6/2026 | Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution. | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability. | |
| Pendiente de análisis | Media (6.9) | 0.09% | — | AMD AgesaAIAMD Ddr5AI | 15/5/2026 | 17/6/2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | AMD Sensor Fusion HUB DriverAI | 15/5/2026 | 17/6/2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash |