Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.33%—Emqx Nanomq15/12/202517/6/2026
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.
AplazadaMedia (6)0.22%—Nanomq NanonnAIEmqx NanomqAI25/11/202517/6/2026
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to…
AplazadaBaja (3)0.28%💥 PoCEmqxAI10/8/202517/6/2026
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl…
AnalizadaAlta (8.8)0.37%—Emqx Nanomq29/7/202517/6/2026
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
AnalizadaAlta (7.5)0.43%—Emqx Nanomq29/7/202517/6/2026
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
AnalizadaAlta (7.5)0.60%—Emqx Nanomq15/7/202517/6/2026
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
ModificadaMedia (6.5)0.33%—Emqx Nanomq14/7/202517/6/2026
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
ModificadaMedia (6.5)0.36%—Emqx Nanomq14/7/202517/6/2026
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
ModificadaAlta (7.5)0.44%—Emqx Nanomq14/7/202517/6/2026
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
AnalizadaMedia (5.3)0.48%—Emqx Neuron7/11/202417/6/2026
A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named…
AnalizadaMedia (5.3)0.66%—Emqx Neuron7/11/202417/6/2026
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a…
ModificadaAlta (7.5)0.49%—Emqx Nanomq12/9/202417/6/2026
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
AnalizadaMedia (6.8)0.33%—Emqx Nanomq22/4/202417/6/2026
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
AnalizadaAlta (7.5)0.56%—Emqx Nanomq17/4/202417/6/2026
Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.
AnalizadaBaja (2.7)0.58%—Emqx Nanomq17/4/202417/6/2026
Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
AnalizadaMedia (6.5)0.65%—Emqx Nanomq26/2/202417/6/2026
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
ModificadaMedia (6.5)0.89%—Emqx17/7/202317/6/2026
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
ModificadaAlta (7.5)0.67%—Emqx Nanomq12/6/202317/6/2026
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
AnalizadaAlta (7.8)0.51%—Emqx Nanomq12/6/202317/6/2026
NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
ModificadaAlta (7.5)0.96%—Emqx Nanomq8/6/202317/6/2026
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.
ModificadaAlta (7.5)1.2%—Emqx Nanomq8/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaAlta (7.5)1.2%—Emqx Nanomq8/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaAlta (7.5)1.1%—Emqx Nanomq6/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaMedia (5.5)0.38%—Emqx Nanomq30/5/202317/6/2026
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources.
ModificadaAlta (7.5)0.84%—Emqx Nanomq4/5/202317/6/2026
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode.
Orbitaley — Vulnerabilidades