Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.37% | — | Emqx Nanomq | 1/1/2026 | 17/6/2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is triggered when NanoMQ acts as a bridge connecting to a remote MQTT… | |
| Analizada | Alta (7.5) | 0.38% | — | Emqx Nanomq | 27/12/2025 | 17/6/2026 | NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2. | |
| Analizada | Alta (8.5) | 0.33% | — | Emqx Nanomq | 15/12/2025 | 17/6/2026 | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription. | |
| Aplazada | Media (6) | 0.22% | — | Nanomq NanonnAIEmqx NanomqAI | 25/11/2025 | 17/6/2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to… | |
| Aplazada | Alta (7.3) | 0.16% | — | Oxford Nanopore Technologies MinknowAI | 23/10/2025 | 17/6/2026 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked… | |
| Aplazada | Media (6.8) | 0.16% | — | Oxford Nanopore Technologies MinknowAI | 23/10/2025 | 17/6/2026 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying it to its final location. This temporary file is created in a directory accessible to all users on the system. An unauthorized local user or… | |
| Analizada | Baja (2) | 0.44% | — | Metaclinic Nanovault | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.37% | — | Emqx Nanomq | 29/7/2025 | 17/6/2026 | An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters. | |
| Analizada | Alta (7.5) | 0.43% | — | Emqx Nanomq | 29/7/2025 | 17/6/2026 | NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message. | |
| Analizada | Alta (7.5) | 0.60% | — | Emqx Nanomq | 15/7/2025 | 17/6/2026 | NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message. | |
| Modificada | Media (6.5) | 0.33% | — | Emqx Nanomq | 14/7/2025 | 17/6/2026 | NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message. | |
| Modificada | Media (6.5) | 0.36% | — | Emqx Nanomq | 14/7/2025 | 17/6/2026 | NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message. | |
| Modificada | Alta (7.5) | 0.44% | — | Emqx Nanomq | 14/7/2025 | 17/6/2026 | A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages. | |
| Aplazada | Alta (7.1) | 0.39% | — | Mayeenul Islam NanosupportAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mayeenul Islam NanoSupport nanosupport allows Reflected XSS.This issue affects NanoSupport: from n/a through <= 0.6.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Mayeenul Islam NanosupportAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through <= 0.6.0. | |
| Aplazada | Media (4.3) | 0.66% | — | NanoidAI | 9/12/2024 | 17/6/2026 | nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. | |
| Aplazada | Media (4.3) | 0.41% | — | NanopbAI | 2/12/2024 | 17/6/2026 | Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, the message contains at least one field with FT_POINTER field type, custom stream callback is used with unknown stream length. and the pb_decode_ex() function is used with flag PB_DECODE_DELIMITED,… | |
| Modificada | Alta (7.5) | 0.49% | — | Emqx Nanomq | 12/9/2024 | 17/6/2026 | An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS). | |
| Modificada | Media (4.2) | 0.33% | — | Yubico Yubikey 5C NFC FirmwareYubico Yubikey 5 NFC FirmwareYubico Yubikey 5C FirmwareYubico Yubikey 5 Nano Firmware+14 | 3/9/2024 | 17/6/2026 | Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the… | |
| Aplazada | Media (6.3) | 0.29% | — | Himalaya Xiaoya Nano Smart SpeakerAI | 29/7/2024 | 9/7/2026 | Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact. | |
| Modificada | Media (5.4) | 0.11% | — | Savignano S-notify | 1/7/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email. | |
| Aplazada | Alta (8.8) | 0.15% | — | Savignano S NotifyAI | 1/7/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email. | |
| Modificada | Media (6.7) | 0.34% | — | GNU NanoRedhat Enterprise Linux | 12/6/2024 | 17/6/2026 | A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious… | |
| Modificada | Crítica (9.8) | 0.75% | — | VIZ Nano ID | 4/6/2024 | 17/6/2026 | nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the… | |
| Analizada | Media (6.8) | 0.33% | — | Emqx Nanomq | 22/4/2024 | 17/6/2026 | A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams. |