Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.86%—Riot-os Riot24/4/202317/6/2026
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a large out of bounds write beyond the packet buffer. The write will create a hard fault…
ModificadaAlta (7.5)0.86%—Riot-os Riot24/4/202317/6/2026
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of bounds write beyond the packet buffer. The write will create a hard fault exception after reaching…
ModificadaCrítica (9.8)0.98%—Riot-os Riot24/4/202317/6/2026
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The overflow can be used to corrupt other…
ModificadaAlta (7.5)1.2%—Riot-os Riot24/4/202317/6/2026
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a NULL pointer dereference. During forwarding of a fragment an uninitialized entry in the…
ModificadaAlta (8.8)0.91%—Alotceriot Ar7088h-a Firmware12/1/202317/6/2026
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution.
ModificadaMedia (5.3)0.45%—Alotceriot Ar7088h-a Firmware12/1/202317/6/2026
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.
ModificadaCrítica (9.8)1.7%—Riot-os Riot3/5/202217/6/2026
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
ModificadaMedia (5.5)0.21%—Riot-os Riot15/9/202117/6/2026
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.
ModificadaAlta (7.5)1.3%—Riot-os Riot18/6/202117/6/2026
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
ModificadaAlta (7.5)1.6%—Riot-os Riot18/6/202117/6/2026
RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information.
ModificadaAlta (7.5)1.3%—Riot-os Riot18/6/202117/6/2026
RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.
ModificadaAlta (7.5)1.3%—Riot-os Riot18/6/202117/6/2026
RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information.
ModificadaAlta (7.5)1.3%—Riot-os Riot18/6/202117/6/2026
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.
ModificadaCrítica (9.8)1.2%—Riot-os Riot6/4/202117/6/2026
RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function.
ModificadaCrítica (9.8)1.3%—Riot-os Riot6/4/202117/6/2026
RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function.
ModificadaCrítica (9.8)1.2%—Riot-os Riot6/4/202117/6/2026
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.
ModificadaCrítica (9.8)45%💥 ExploitCommscope Ruckus Vriot26/10/202017/6/2026
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
ModificadaAlta (8.8)12%💥 PoCCommscope Ruckus Vriot26/10/202017/6/2026
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
ModificadaCrítica (9.8)1.5%—Riot-os Riot7/7/202017/6/2026
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_estimate_decode_size() function calculates the expected decoded size with an…
ModificadaAlta (7.8)0.51%—Patriotmemory Viper RGB Firmware6/3/202017/6/2026
Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
ModificadaAlta (7.8)0.51%—Patriotmemory Viper RGB Driver21/2/202017/6/2026
A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges.
ModificadaMedia (6.1)0.69%—Usriot Usr-wifi232-s FirmwareUsriot Usr-wifi232-t FirmwareUsriot Usr-wifi232-g2 FirmwareUsriot Usr-wifi232-h Firmware6/1/202017/6/2026
A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi…
ModificadaAlta (7.1)0.41%💥 PoCPatriotmemory Viper RGB Firmware9/11/201917/6/2026
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and…
ModificadaAlta (7.5)1.4%—Riot-os Riot9/10/201917/6/2026
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.
ModificadaAlta (7.5)1.5%—Riot-os Riot24/9/201917/6/2026
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server response. To do so, the attacker needs to know the MQTT MsgID of a pending MQTT protocol message and the ephemeral port…
Orbitaley — Vulnerabilidades