Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+28 | 4/5/2026 | 17/6/2026 | In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504. | |
| Analizada | Media (6.5) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+47 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;… | |
| Analizada | Media (6.5) | 0.22% | — | Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+64 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue… | |
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+18 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. | |
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+13 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. | |
| Analizada | Media (4.3) | 0.19% | — | Mediatek Mt6813 Firmware | 7/4/2026 | 17/6/2026 | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899. | |
| Analizada | Alta (8.8) | 0.34% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 FirmwareMediatek Mt6833 Firmware+58 | 7/4/2026 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analizada | Alta (8) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6779 FirmwareMediatek Mt6781 Firmware+54 | 7/4/2026 | 24/7/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analizada | Media (6.5) | 0.31% | — | Mediatek Mt6813 FirmwareMediatek Mt6815 FirmwareMediatek Mt6835 FirmwareMediatek Mt6878 Firmware+15 | 7/4/2026 | 24/7/2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID:… | |
| Analizada | Media (6.7) | 0.13% | — | Mediatek Nbiot SDK | 2/3/2026 | 17/6/2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970. | |
| Analizada | Alta (7.5) | 0.23% | — | Mediatek Lr12aMediatek Lr13Mediatek Nr15Mediatek Nr16+1 | 2/3/2026 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analizada | Alta (8.8) | 0.24% | — | Mediatek Software Development KITOpenwrt | 2/3/2026 | 17/6/2026 | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151. | |
| Modificada | Alta (7.8) | 0.13% | — | Mediatek Nbiot SDK | 2/3/2026 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956. | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738293;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738313;… | |
| Modificada | Media (6.5) | 0.79% | — | Mediatek Nbiot SDKMediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461663 / WCNCR00463309; Issue ID:… | |
| Analizada | Alta (8.8) | 0.30% | — | Mediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue ID: MSV-4758. | |
| Analizada | Crítica (9.3) | 0.18% | — | Mediatek Nbiot SDK | 2/2/2026 | 17/6/2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905. | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01726634; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01688495; Issue… | |
| Modificada | Media (6.5) | 0.50% | 💥 PoC | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note:… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00693083;… | |
| Modificada | Alta (7.5) | 0.73% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738310; Issue… |