Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.86% | — | Riot-os Riot | 24/4/2023 | 17/6/2026 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a large out of bounds write beyond the packet buffer. The write will create a hard fault… | |
| Modificada | Alta (7.5) | 0.86% | — | Riot-os Riot | 24/4/2023 | 17/6/2026 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of bounds write beyond the packet buffer. The write will create a hard fault exception after reaching… | |
| Modificada | Crítica (9.8) | 0.98% | — | Riot-os Riot | 24/4/2023 | 17/6/2026 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The overflow can be used to corrupt other… | |
| Modificada | Alta (7.5) | 1.2% | — | Riot-os Riot | 24/4/2023 | 17/6/2026 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a NULL pointer dereference. During forwarding of a fragment an uninitialized entry in the… | |
| Modificada | Alta (8.8) | 0.91% | — | Alotceriot Ar7088h-a Firmware | 12/1/2023 | 17/6/2026 | Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution. | |
| Modificada | Media (5.3) | 0.45% | — | Alotceriot Ar7088h-a Firmware | 12/1/2023 | 17/6/2026 | Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name. | |
| Modificada | Crítica (9.8) | 1.7% | — | Riot-os Riot | 3/5/2022 | 17/6/2026 | RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | |
| Modificada | Media (5.5) | 0.21% | — | Riot-os Riot | 15/9/2021 | 17/6/2026 | In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots. | |
| Modificada | Alta (7.5) | 1.3% | — | Riot-os Riot | 18/6/2021 | 17/6/2026 | RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.6% | — | Riot-os Riot | 18/6/2021 | 17/6/2026 | RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.3% | — | Riot-os Riot | 18/6/2021 | 17/6/2026 | RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.3% | — | Riot-os Riot | 18/6/2021 | 17/6/2026 | RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.3% | — | Riot-os Riot | 18/6/2021 | 17/6/2026 | RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.2% | — | Riot-os Riot | 6/4/2021 | 17/6/2026 | RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function. | |
| Modificada | Crítica (9.8) | 1.3% | — | Riot-os Riot | 6/4/2021 | 17/6/2026 | RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function. | |
| Modificada | Crítica (9.8) | 1.2% | — | Riot-os Riot | 6/4/2021 | 17/6/2026 | RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c. | |
| Modificada | Crítica (9.8) | 45% | 💥 Exploit | Commscope Ruckus Vriot | 26/10/2020 | 17/6/2026 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header. | |
| Modificada | Alta (8.8) | 12% | 💥 PoC | Commscope Ruckus Vriot | 26/10/2020 | 17/6/2026 | Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py. | |
| Modificada | Crítica (9.8) | 1.5% | — | Riot-os Riot | 7/7/2020 | 17/6/2026 | RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_estimate_decode_size() function calculates the expected decoded size with an… | |
| Modificada | Alta (7.8) | 0.51% | — | Patriotmemory Viper RGB Firmware | 6/3/2020 | 17/6/2026 | Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.51% | — | Patriotmemory Viper RGB Driver | 21/2/2020 | 17/6/2026 | A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges. | |
| Modificada | Media (6.1) | 0.69% | — | Usriot Usr-wifi232-s FirmwareUsriot Usr-wifi232-t FirmwareUsriot Usr-wifi232-g2 FirmwareUsriot Usr-wifi232-h Firmware | 6/1/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi… | |
| Modificada | Alta (7.1) | 0.41% | 💥 PoC | Patriotmemory Viper RGB Firmware | 9/11/2019 | 17/6/2026 | The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and… | |
| Modificada | Alta (7.5) | 1.4% | — | Riot-os Riot | 9/10/2019 | 17/6/2026 | In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted. | |
| Modificada | Alta (7.5) | 1.5% | — | Riot-os Riot | 24/9/2019 | 17/6/2026 | RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server response. To do so, the attacker needs to know the MQTT MsgID of a pending MQTT protocol message and the ephemeral port… |