Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.56% | — | Emqx Nanomq | 17/4/2024 | 17/6/2026 | Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service. | |
| Analizada | Baja (2.7) | 0.58% | — | Emqx Nanomq | 17/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams. | |
| Analizada | Media (6.1) | 0.21% | — | Savignano S-notify | 10/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate. | |
| Analizada | Media (5.2) | 0.14% | — | Savignano S-notify | 10/4/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link. | |
| Analizada | Media (6.5) | 0.65% | — | Emqx Nanomq | 26/2/2024 | 17/6/2026 | nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c. | |
| Analizada | Media (5.4) | 0.17% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.… | |
| Analizada | Media (5.4) | 0.17% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.… | |
| Modificada | Alta (7.1) | 0.19% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If… | |
| Modificada | Media (5.7) | 0.40% | — | Autelrobotics EVO Nano Drone Firmware | 6/1/2024 | 17/6/2026 | Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS). | |
| Modificada | Media (6.5) | 0.29% | — | Autelrobotics EVO Nano Drone Firmware | 16/11/2023 | 17/6/2026 | Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones. | |
| Modificada | Alta (7.5) | 0.59% | — | Nanoleaf Lightstrip Firmware | 31/10/2023 | 17/6/2026 | An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Thinkpad X13 Yoga GEN 2 FirmwareLenovo Thinkpad X13 Yoga GEN 1 FirmwareLenovo Thinkpad X13 GEN 3 FirmwareLenovo Thinkpad X13 GEN 2 Firmware+50 | 30/10/2023 | 17/6/2026 | An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+81 | 30/10/2023 | 17/6/2026 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.78% | — | Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+5 | 10/10/2023 | 17/6/2026 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a… | |
| Modificada | Media (6.7) | 0.16% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+81 | 26/6/2023 | 17/6/2026 | A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.95% | — | Nanopb Project Nanopb | 17/6/2023 | 17/6/2026 | Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string. | |
| Modificada | Alta (7.5) | 0.67% | — | Emqx Nanomq | 12/6/2023 | 17/6/2026 | NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c. | |
| Analizada | Alta (7.8) | 0.51% | — | Emqx Nanomq | 12/6/2023 | 17/6/2026 | NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages. | |
| Modificada | Alta (7.5) | 0.96% | — | Emqx Nanomq | 8/6/2023 | 17/6/2026 | A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack. | |
| Modificada | Alta (7.5) | 1.2% | — | Emqx Nanomq | 8/6/2023 | 17/6/2026 | A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack. | |
| Modificada | Alta (7.5) | 1.2% | — | Emqx Nanomq | 8/6/2023 | 17/6/2026 | A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack. | |
| Modificada | Alta (7.5) | 1.1% | — | Emqx Nanomq | 6/6/2023 | 17/6/2026 | A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack. | |
| Modificada | Media (5.5) | 0.38% | — | Emqx Nanomq | 30/5/2023 | 17/6/2026 | A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources. | |
| Modificada | Alta (7.5) | 0.84% | — | Emqx Nanomq | 4/5/2023 | 17/6/2026 | In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode. | |
| Modificada | Alta (7.5) | 0.73% | — | Emqx Nanomq | 4/5/2023 | 17/6/2026 | In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c |