Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.91% | — | Bluetooth Core SpecificationBluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. | |
| Modificada | Media (5.4) | 0.88% | — | Bluetooth Core SpecificationFedoraproject FedoraIntel Ax210 FirmwareIntel Ax201 Firmware+13 | 24/5/2021 | 17/6/2026 | Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN. | |
| Modificada | Alta (8.1) | 0.64% | — | Elementary Switchboard Bluetooth PlugFedoraproject Fedora | 12/3/2021 | 17/6/2026 | Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | Bluetooth Core Specification | 11/9/2020 | 17/6/2026 | Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one transport, either LE or BR/EDR, and replace a bonding already established on the… | |
| Modificada | Media (6.5) | 1.2% | — | Silabs Bluetooth LOW Energy Software Development KIT | 20/8/2020 | 17/6/2026 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles. | |
| Modificada | Alta (8.8) | 3.2% | — | Silabs Bluetooth LOW Energy Software Development KIT | 20/8/2020 | 17/6/2026 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles. | |
| Modificada | Media (5.4) | 2.4% | 💥 PoC | Bluetooth CoreOpensuse Leap | 19/5/2020 | 17/6/2026 | Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave… | |
| Modificada | Media (6.3) | 0.66% | — | Bluetooth Core | 19/5/2020 | 17/6/2026 | Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer device and an end-user erroneously completes both pairing procedures with the MITM using… | |
| Modificada | Crítica (9.8) | 2.1% | — | Postoaktraffic Awam Bluetooth Field Device Firmware | 17/2/2020 | 17/6/2026 | Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter. | |
| Modificada | Media (6.5) | 0.68% | — | Yalehome Yale Bluetooth KEY | 16/10/2019 | 17/6/2026 | The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale… | |
| Analizada | Media (6.8) | 0.81% | — | TI Wl18xx Bluetooth Service PackGoogle AndroidApple Iphone OSApple MAC OS X | 7/8/2018 | 17/6/2026 | Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a… | |
| Modificada | Alta (7.5) | 1.1% | — | Bavarian Motor Works Bluetooth Stack | 23/5/2017 | 17/6/2026 | The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name. | |
| Modificada | Alta (7.8) | 0.47% | — | Intel Wireless Bluetooth Drivers | 8/12/2016 | 17/6/2026 | Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges. | |
| Modificada | Media (6.9) | 0.38% | — | Toshiba Bluetooth StackToshiba Service Station | 28/2/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Alta (9.3) | 6.4% | — | Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software | 21/1/2014 | 16/6/2026 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed… | |
| Modificada | Alta (7.6) | 1.5% | — | Postoaktraffic Awam Bluetooth Reader | 8/12/2012 | 16/6/2026 | Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value. | |
| Modificada | Alta (8.8) | 5.9% | — | Bluetooth StackMicrosoft Windows 7Microsoft Windows Vista | 13/7/2011 | 16/6/2026 | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack… | |
| Modificada | Alta (10) | 2.5% | — | Broadcom Widcomm Bluetooth | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Alta (10) | 2.3% | — | Toshiba Bluetooth | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Media (5.4) | 0.73% | — | Widcomm Bluetooth FOR Windows | 31/12/2006 | 16/6/2026 | Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter. | |
| Modificada | Alta (10) | 1.6% | — | Bluesoil Bluetooth | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Bluesoil Bluetooth stack has unknown impact and attack vectors. | |
| Modificada | Alta (7.8) | 3.9% | — | Broadcom Widcomm Bluetooth | 31/12/2006 | 16/6/2026 | Widcomm Bluetooth for Windows (BTW) before 4.0.1.1500 allows remote attackers to listen to and record conversations, aka the CarWhisperer attack. | |
| Modificada | Alta (10) | 31% | — | Broadcom Widcomm BluetoothMicrosoft Windows Embedded CompactMicrosoft Windows Mobile | 31/12/2006 | 16/6/2026 | Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows… | |
| Modificada | Alta (7.9) | 0.86% | — | Broadcom Bluetooth Stack | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Broadcom Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Alta (10) | 1.4% | — | Toshiba Bluetooth Stack | 31/10/2006 | 16/6/2026 | Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405. |