Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1540 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.11%—Nvidia GPU Display DriverAI30/9/202630/9/2026
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service.
Pendiente de análisisAlta (7.8)0.15%—Nvidia GPU Display DriverAI30/9/20261/10/2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of…
Pendiente de análisisAlta (7.8)0.13%—Nvidia GPU Display DriverAI30/9/202630/9/2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisMedia (5.2)0.12%—Image Scanner DriverAI30/9/202630/9/2026
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
En análisisAlta (7.8)0.12%—NXP Mcux Lpadc DriverAIZephyrproject ZephyrAI28/9/202630/9/2026
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to…
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202630/9/2026
In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202629/9/2026
Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09
Pendiente de análisisAlta (7.8)0.11%—Windriver VxworksAI28/9/202629/9/2026
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202628/9/2026
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.
Pendiente de análisisMedia (5.3)0.13%—Mongodb Python DriverAI24/9/202624/9/2026
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver…
Pendiente de análisisAlta (8.3)0.37%—Mongodb C DriverAI24/9/202624/9/2026
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate…
Pendiente de análisisMedia (6.3)0.30%—Mongodb PHP DriverAI24/9/202624/9/2026
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database…
AplazadaCrítica (9.3)0.16%—Moore Threads MTT S80 Driver PackageAI21/9/202622/9/2026
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about…
AplazadaCrítica (9.3)0.20%—Moore Threads MTT S80 Driver PackageAI21/9/202622/9/2026
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about…
AplazadaAlta (8.8)0.58%—Wpcloudplugins USE Your DriveAIWpcloudplugins OUT OF THE BOXAIWpcloudplugins Share ONE DriveAIWpcloudplugins Lets BOXAI18/9/202621/9/2026
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users…
AnalizadaMedia (6.9)0.40%—Mongodb C Driver17/9/202625/9/2026
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size)…
AnalizadaMedia (6.3)0.32%—Mongodb C Driver17/9/202625/9/2026
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted…
AnalizadaCrítica (9.2)0.47%—Mongodb C Driver17/9/202629/9/2026
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic…
Pendiente de análisisAlta (8.8)0.16%—Avast Sandbox Minifilter DriverAI16/9/202617/9/2026
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened…
Pendiente de análisisMedia (6.8)0.18%—ITE It51xxx I2C DriverAI14/9/202618/9/2026
The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c. The copy…
AplazadaMedia (6.8)0.11%—Panasonic Industry USB DriverAI14/9/202618/9/2026
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.
Pendiente de análisisMedia (4.2)0.13%—Samsung Exynos 1580AISamsung Custos DriverAI14/9/202622/9/2026
An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.
AnalizadaMedia (6.1)0.27%—Mongodb C Driver10/9/202616/9/2026
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected…
AnalizadaMedia (5.7)0.10%—Mongodb C Driver10/9/202616/9/2026
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly.…
AnalizadaMedia (6.1)0.46%—Mongodb C++ Driver10/9/202616/9/2026
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an…