Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.60%—Dronetag Drone Scanner6/2/202417/6/2026
An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.
ModificadaAlta (8.2)0.63%—Sorenfriis Opendroneid OSM6/2/202417/6/2026
An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.
ModificadaMedia (5.7)0.40%—Autelrobotics EVO Nano Drone Firmware6/1/202417/6/2026
Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
ModificadaMedia (6.5)0.29%—Autelrobotics EVO Nano Drone Firmware16/11/202317/6/2026
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.
ModificadaMedia (4.3)0.52%—Dronecode PX4 Drone Autopilot13/11/202317/6/2026
PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A malicious user may create an RC packet remotely and that packet goes…
ModificadaCrítica (9.8)0.63%—Dronecode PX4 Drone Autopilot31/10/202317/6/2026
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading…
ModificadaAlta (8.1)0.35%—Bluemark Dronescout Ds230 Firmware11/7/202317/6/2026
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID…
ModificadaAlta (8.1)0.36%—Bluemark Dronescout Ds230 Firmware11/7/202317/6/2026
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update…
ModificadaMedia (6.8)0.32%—Bluemark Dronescout Ds230 Firmware11/7/202317/6/2026
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real…
ModificadaAlta (7.5)0.81%—Dronecode PX4 Drone Autopilot6/7/202317/6/2026
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
ModificadaAlta (7.5)0.96%—Dronecode PX4 Drone AutopilotYuneec Mantis Q Firmware9/3/202317/6/2026
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
ModificadaCrítica (9.8)1.5%—Dronecode Micro AIR Vehicle Link20/8/202017/6/2026
The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOT_VERSION message. Since this negotiation depends on the answer, an attacker…
ModificadaCrítica (9.8)1.8%—Dronecode Micro AIR Vehicle Link3/7/202017/6/2026
The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more. According to literature, version 2.0 optionally allows for package signing which…
ModificadaAlta (7.5)0.71%—Dronecode Micro AIR Vehicle Link3/7/202017/6/2026
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MAVLink is a header-based protocol that does not perform encryption to improve transfer (and reception speed) and…
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Orbitaley — Vulnerabilidades