Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.47% | — | Free5gc PCF | 23/1/2026 | 17/6/2026 | Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId. | |
| Analizada | Crítica (9.1) | 0.35% | — | Free5gc NRF | 23/1/2026 | 17/6/2026 | An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any… | |
| Analizada | Alta (7.5) | 0.56% | — | Free5gc | 18/12/2025 | 17/6/2026 | The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode.Sess() when a… | |
| Analizada | Alta (7.5) | 0.44% | — | Free5gc | 18/12/2025 | 17/6/2026 | An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request. | |
| Analizada | Alta (7.5) | 0.35% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API. | |
| Analizada | Media (6.5) | 0.36% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API. | |
| Analizada | Media (6.5) | 0.24% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API. | |
| Analizada | Alta (7.5) | 0.40% | — | Free5gc | 12/11/2025 | 17/6/2026 | free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes. | |
| Analizada | Alta (7.5) | 0.42% | — | Free5gc | 23/9/2025 | 17/6/2026 | Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow. | |
| Analizada | Media (5.4) | 0.35% | 💥 PoC | Free5gc | 29/5/2025 | 17/6/2026 | Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components | |
| Modificada | Alta (7.5) | 1.0% | — | Free5gc | 22/12/2023 | 17/6/2026 | An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message. | |
| Modificada | Media (5.5) | 0.25% | — | Free5gc | 16/11/2023 | 17/6/2026 | An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component. | |
| Modificada | Alta (7.5) | 0.74% | — | Free5gc | 15/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes. | |
| Modificada | Alta (7.5) | 0.85% | — | Free5gc | 15/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero. | |
| Modificada | Alta (7.5) | 0.78% | — | Free5gcFree5gc SMFFree5gc UPF | 13/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages. | |
| Modificada | Alta (7.5) | 0.41% | — | Free5gc UDM | 23/10/2023 | 17/6/2026 | pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the… | |
| Modificada | Crítica (9.8) | 0.44% | — | Free5gc | 2/10/2023 | 17/6/2026 | Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote… | |
| Modificada | Alta (7.5) | 0.77% | — | Free5gc | 18/11/2022 | 17/6/2026 | In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Free5gc | 25/10/2022 | 17/6/2026 | Free5gc v3.2.1 is vulnerable to Information disclosure. | |
| Modificada | Media (5.5) | 0.75% | — | Free5gc | 24/10/2022 | 17/6/2026 | In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString. |