Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
5132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.40% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría conducir a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Analizada | Media (6.5) | 0.48% | — | Mediatek Nr15Mediatek Nr16 | 2/12/2025 | 17/6/2026 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673760;… | |
| Analizada | Media (4.9) | 0.51% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673755; Issue… | |
| Modificada | Media (6.5) | 0.25% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. La interacción del usuario… | |
| Modificada | Media (6.5) | 0.25% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673749; Issue ID:… | |
| Analizada | Media (5.3) | 0.49% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689251;… | |
| Analizada | Media (5.3) | 0.49% | — | Mediatek Nr15Mediatek Nr16 | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689252; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01270690; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una falta de verificación de límites. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría conducir a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Analizada | Media (5.3) | 0.37% | — | Mediatek Nr15 | 2/12/2025 | 25/9/2026 | En el Módem, existe una posible caída de la aplicación debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita… | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream. | |
| Aplazada | Media (6.9) | 0.35% | — | MediacrushAI | 1/12/2025 | 3/9/2026 | A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely. | |
| Aplazada | Alta (8.7) | 0.53% | — | Dongyoung Media Dm-ap240t/wAI | 26/11/2025 | 17/6/2026 | Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed… | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Analizada | Alta (7.3) | 0.15% | — | Nvidia Nemo | 25/11/2025 | 17/6/2026 | NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution. | |
| Analizada | Alta (7.8) | 0.20% | — | Nvidia Nemo | 25/11/2025 | 17/6/2026 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Alta (7.6) | 0.29% | — | Nvidia Nemo Agent Toolkit UI FOR WEBAI | 25/11/2025 | 17/6/2026 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |
| Analizada | Baja (3.3) | 0.14% | — | Nvidia DGX OS | 25/11/2025 | 17/6/2026 | NVIDIA DGX Spark GB10 contiene una vulnerabilidad en el firmware SROOT, donde un atacante podría causar que un recurso sea reutilizado. Un exploit exitoso de esta vulnerabilidad podría llevar a la revelación de información. | |
| Analizada | Baja (3.8) | 0.14% | — | Nvidia DGX OS | 25/11/2025 | 17/6/2026 | NVIDIA DGX Spark GB10 contiene una vulnerabilidad en el firmware SROOT, donde un atacante podría causar un comportamiento incorrecto del flujo de control. Un exploit exitoso de esta vulnerabilidad podría conducir a la manipulación de datos. | |
| Analizada | Baja (3.3) | 0.14% | — | Nvidia DGX OS | 25/11/2025 | 17/6/2026 | NVIDIA DGX Spark GB10 contiene una vulnerabilidad en el firmware SROOT, donde un atacante podría causar la reutilización de un recurso. Un exploit exitoso de esta vulnerabilidad podría llevar a la revelación de información. |