Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.37%—Emqx Nanomq1/1/202617/6/2026
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is triggered when NanoMQ acts as a bridge connecting to a remote MQTT…
AnalizadaAlta (7.5)0.38%—Emqx Nanomq27/12/202517/6/2026
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.
AnalizadaAlta (8.5)0.33%—Emqx Nanomq15/12/202517/6/2026
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.
AplazadaMedia (6)0.22%—Nanomq NanonnAIEmqx NanomqAI25/11/202517/6/2026
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to…
AplazadaAlta (7.3)0.16%—Oxford Nanopore Technologies MinknowAI23/10/202517/6/2026
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked…
AplazadaMedia (6.8)0.16%—Oxford Nanopore Technologies MinknowAI23/10/202517/6/2026
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying it to its final location. This temporary file is created in a directory accessible to all users on the system. An unauthorized local user or…
AnalizadaBaja (2)0.44%—Metaclinic Nanovault5/8/202517/6/2026
A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (8.8)0.37%—Emqx Nanomq29/7/202517/6/2026
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
AnalizadaAlta (7.5)0.43%—Emqx Nanomq29/7/202517/6/2026
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
AnalizadaAlta (7.5)0.60%—Emqx Nanomq15/7/202517/6/2026
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
ModificadaMedia (6.5)0.33%—Emqx Nanomq14/7/202517/6/2026
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
ModificadaMedia (6.5)0.36%—Emqx Nanomq14/7/202517/6/2026
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
ModificadaAlta (7.5)0.44%—Emqx Nanomq14/7/202517/6/2026
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
AplazadaAlta (7.1)0.39%—Mayeenul Islam NanosupportAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mayeenul Islam NanoSupport nanosupport allows Reflected XSS.This issue affects NanoSupport: from n/a through <= 0.6.0.
AplazadaMedia (4.3)0.23%—Mayeenul Islam NanosupportAI31/3/202517/6/2026
Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through <= 0.6.0.
AplazadaMedia (4.3)0.66%—NanoidAI9/12/202417/6/2026
nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
AplazadaMedia (4.3)0.41%—NanopbAI2/12/202417/6/2026
Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, the message contains at least one field with FT_POINTER field type, custom stream callback is used with unknown stream length. and the pb_decode_ex() function is used with flag PB_DECODE_DELIMITED,…
ModificadaAlta (7.5)0.49%—Emqx Nanomq12/9/202417/6/2026
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
ModificadaMedia (4.2)0.33%—Yubico Yubikey 5C NFC FirmwareYubico Yubikey 5 NFC FirmwareYubico Yubikey 5C FirmwareYubico Yubikey 5 Nano Firmware+143/9/202417/6/2026
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the…
AplazadaMedia (6.3)0.29%—Himalaya Xiaoya Nano Smart SpeakerAI29/7/20249/7/2026
Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact.
ModificadaMedia (5.4)0.11%—Savignano S-notify1/7/202417/6/2026
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
AplazadaAlta (8.8)0.15%—Savignano S NotifyAI1/7/202417/6/2026
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
ModificadaMedia (6.7)0.34%—GNU NanoRedhat Enterprise Linux12/6/202417/6/2026
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious…
ModificadaCrítica (9.8)0.75%—VIZ Nano ID4/6/202417/6/2026
nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the…
AnalizadaMedia (6.8)0.33%—Emqx Nanomq22/4/202417/6/2026
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
Orbitaley — Vulnerabilidades