Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.56%—Emqx Nanomq17/4/202417/6/2026
Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.
AnalizadaBaja (2.7)0.58%—Emqx Nanomq17/4/202417/6/2026
Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
AnalizadaMedia (6.1)0.21%—Savignano S-notify10/4/202417/6/2026
Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.
AnalizadaMedia (5.2)0.14%—Savignano S-notify10/4/202417/6/2026
Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.
AnalizadaMedia (6.5)0.65%—Emqx Nanomq26/2/202417/6/2026
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
AnalizadaMedia (5.4)0.17%—Savignano S-notify9/1/202417/6/2026
An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.…
AnalizadaMedia (5.4)0.17%—Savignano S-notify9/1/202417/6/2026
An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.…
ModificadaAlta (7.1)0.19%—Savignano S-notify9/1/202417/6/2026
An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If…
ModificadaMedia (5.7)0.40%—Autelrobotics EVO Nano Drone Firmware6/1/202417/6/2026
Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
ModificadaMedia (6.5)0.29%—Autelrobotics EVO Nano Drone Firmware16/11/202317/6/2026
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.
ModificadaAlta (7.5)0.59%—Nanoleaf Lightstrip Firmware31/10/202317/6/2026
An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.
ModificadaMedia (6.7)0.19%—Lenovo Thinkpad X13 Yoga GEN 2 FirmwareLenovo Thinkpad X13 Yoga GEN 1 FirmwareLenovo Thinkpad X13 GEN 3 FirmwareLenovo Thinkpad X13 GEN 2 Firmware+5030/10/202317/6/2026
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.19%—Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+8130/10/202317/6/2026
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaMedia (6.7)0.16%—Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+8126/6/202317/6/2026
A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaCrítica (9.8)0.95%—Nanopb Project Nanopb17/6/202317/6/2026
Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.
ModificadaAlta (7.5)0.67%—Emqx Nanomq12/6/202317/6/2026
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
AnalizadaAlta (7.8)0.51%—Emqx Nanomq12/6/202317/6/2026
NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
ModificadaAlta (7.5)0.96%—Emqx Nanomq8/6/202317/6/2026
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.
ModificadaAlta (7.5)1.2%—Emqx Nanomq8/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaAlta (7.5)1.2%—Emqx Nanomq8/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaAlta (7.5)1.1%—Emqx Nanomq6/6/202317/6/2026
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
ModificadaMedia (5.5)0.38%—Emqx Nanomq30/5/202317/6/2026
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources.
ModificadaAlta (7.5)0.84%—Emqx Nanomq4/5/202317/6/2026
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode.
ModificadaAlta (7.5)0.73%—Emqx Nanomq4/5/202317/6/2026
In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c
Orbitaley — Vulnerabilidades