Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.91%—Bluetooth Core SpecificationBluetooth Mesh Profile24/5/202117/6/2026
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.
ModificadaMedia (5.4)0.88%—Bluetooth Core SpecificationFedoraproject FedoraIntel Ax210 FirmwareIntel Ax201 Firmware+1324/5/202117/6/2026
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
ModificadaAlta (8.1)0.64%—Elementary Switchboard Bluetooth PlugFedoraproject Fedora12/3/202117/6/2026
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers…
ModificadaMedia (5.9)7.1%💥 PoCBluetooth Core Specification11/9/202017/6/2026
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one transport, either LE or BR/EDR, and replace a bonding already established on the…
ModificadaMedia (6.5)1.2%—Silabs Bluetooth LOW Energy Software Development KIT20/8/202017/6/2026
Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.
ModificadaAlta (8.8)3.2%—Silabs Bluetooth LOW Energy Software Development KIT20/8/202017/6/2026
Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.
ModificadaMedia (5.4)2.4%💥 PoCBluetooth CoreOpensuse Leap19/5/202017/6/2026
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave…
ModificadaMedia (6.3)0.66%—Bluetooth Core19/5/202017/6/2026
Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer device and an end-user erroneously completes both pairing procedures with the MITM using…
ModificadaCrítica (9.8)2.1%—Postoaktraffic Awam Bluetooth Field Device Firmware17/2/202017/6/2026
Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.
ModificadaMedia (6.5)0.68%—Yalehome Yale Bluetooth KEY16/10/201917/6/2026
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale…
AnalizadaMedia (6.8)0.81%—TI Wl18xx Bluetooth Service PackGoogle AndroidApple Iphone OSApple MAC OS X7/8/201817/6/2026
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a…
ModificadaAlta (7.5)1.1%—Bavarian Motor Works Bluetooth Stack23/5/201717/6/2026
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
ModificadaAlta (7.8)0.47%—Intel Wireless Bluetooth Drivers8/12/201617/6/2026
Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges.
ModificadaMedia (6.9)0.38%—Toshiba Bluetooth StackToshiba Service Station28/2/201517/6/2026
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
ModificadaAlta (9.3)6.4%—Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software21/1/201416/6/2026
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed…
ModificadaAlta (7.6)1.5%—Postoaktraffic Awam Bluetooth Reader8/12/201216/6/2026
Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value.
ModificadaAlta (8.8)5.9%—Bluetooth StackMicrosoft Windows 7Microsoft Windows Vista13/7/201116/6/2026
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack…
ModificadaAlta (10)2.5%—Broadcom Widcomm Bluetooth31/12/200616/6/2026
Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
ModificadaAlta (10)2.3%—Toshiba Bluetooth31/12/200616/6/2026
Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
ModificadaMedia (5.4)0.73%—Widcomm Bluetooth FOR Windows31/12/200616/6/2026
Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter.
ModificadaAlta (10)1.6%—Bluesoil Bluetooth31/12/200616/6/2026
Unspecified vulnerability in the Bluesoil Bluetooth stack has unknown impact and attack vectors.
ModificadaAlta (7.8)3.9%—Broadcom Widcomm Bluetooth31/12/200616/6/2026
Widcomm Bluetooth for Windows (BTW) before 4.0.1.1500 allows remote attackers to listen to and record conversations, aka the CarWhisperer attack.
ModificadaAlta (10)31%—Broadcom Widcomm BluetoothMicrosoft Windows Embedded CompactMicrosoft Windows Mobile31/12/200616/6/2026
Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows…
ModificadaAlta (7.9)0.86%—Broadcom Bluetooth Stack31/12/200616/6/2026
Unspecified vulnerability in the Broadcom Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
ModificadaAlta (10)1.4%—Toshiba Bluetooth Stack31/10/200616/6/2026
Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405.
Orbitaley — Vulnerabilidades