Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Tesla Model 3 FirmwareTesla Model S FirmwareTesla Model X Firmware | 27/3/2022 | 17/6/2026 | Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended | |
| Modificada | Media (5.5) | 0.21% | — | Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+5 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash. | |
| Modificada | Media (6.1) | 0.23% | — | Nvidia GeforceNvidia GPU Display DriverNvidia NVSNvidia Quadro+2 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service. | |
| Modificada | Media (6.1) | 0.23% | — | Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+4 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service. | |
| Modificada | Crítica (9.8) | 2.2% | — | Teslamate | 24/1/2022 | 17/6/2026 | TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure. | |
| Modificada | Media (4.1) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure. | |
| Modificada | Alta (7.5) | 0.31% | — | Nvidia Geforce GT 605Nvidia Geforce GT 610Nvidia Geforce GT 620Nvidia Geforce GT 625+59 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact… | |
| Modificada | Alta (7.5) | 0.28% | — | Nvidia Geforce GTX 950Nvidia Geforce GTX 960Nvidia Geforce GTX 970Nvidia Geforce GTX 980+31 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of… | |
| Modificada | Media (4.4) | 0.20% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+103 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure. | |
| Modificada | Alta (8.8) | 1.2% | — | Tesla Solarcity Solar Monitoring Gateway | 18/2/2021 | 17/6/2026 | Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account. | |
| Modificada | Media (4.6) | 0.21% | — | Tesla Model X Firmware | 30/11/2020 | 17/6/2026 | Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob. | |
| Modificada | Media (4.6) | 0.41% | — | Tesla Model X Firmware | 30/11/2020 | 17/6/2026 | Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up action. (The full VIN is visible from outside the vehicle.) | |
| Modificada | Media (6.5) | 0.41% | — | Tesla Model X Firmware | 30/11/2020 | 17/6/2026 | Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an unlock code from a secure enclave chip. | |
| Modificada | Media (6.5) | 1.2% | — | Tesla Model 3 Firmware | 23/7/2020 | 17/6/2026 | Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate this issue | |
| Modificada | Media (4.7) | 0.27% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service. | |
| Modificada | Alta (7.8) | 0.35% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce ExperienceNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure. | |
| Modificada | Alta (7.8) | 0.47% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure. | |
| Modificada | Alta (7.8) | 0.32% | — | Nvidia Quadro FirmwareNvidia Geforce FirmwareNvidia Tesla FirmwareNvidia NVS Firmware | 24/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges. | |
| Modificada | Media (6.5) | 2.6% | 💥 PoC | Tesla Model 3 WEB Interface | 20/3/2020 | 17/6/2026 | The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other… | |
| Modificada | Alta (7.8) | 0.37% | — | Nvidia Quadro FirmwareNvidia Geforce ExperienceNvidia Tesla Firmware | 11/3/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure. |