Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.55%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+114/5/202517/6/2026
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (8.2)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/5/202517/6/2026
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7)0.15%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/5/202517/6/2026
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.70%—Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in30/4/202517/6/2026
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
ModificadaMedia (6.5)3.2%—Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in30/4/202517/6/2026
The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
AnalizadaMedia (5.5)0.25%—Adobe XMP Toolkit Software Development KIT8/4/202517/6/2026
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.24%—Adobe XMP Toolkit Software Development KIT8/4/202517/6/2026
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.24%—Adobe XMP Toolkit Software Development KIT8/4/202517/6/2026
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.25%—Adobe XMP Toolkit Software Development KIT8/4/202517/6/2026
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.24%—Adobe XMP Toolkit Software Development KIT8/4/202517/6/2026
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+18/4/202517/6/2026
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.42%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+18/4/202517/6/2026
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (5.5)0.16%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop8/4/202517/6/2026
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.
ModificadaMedia (5.2)0.24%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+28/4/202517/6/2026
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.
ModificadaMedia (5.2)0.26%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+28/4/202517/6/2026
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.
AnalizadaAlta (7.5)0.54%—Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+37/4/202517/6/2026
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406217; Issue ID: MSV-2773.
AnalizadaAlta (7.5)0.54%—Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+17/4/202517/6/2026
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00408868; Issue ID: MSV-3031.
AnalizadaCrítica (9.8)0.81%—Mediatek Software Development KITMediatek Mt7622Mediatek Mt7915Mediatek Mt7916+47/4/202517/6/2026
In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.
AnalizadaCrítica (9.8)0.78%—Aliconnect Software Development KIT28/3/202517/6/2026
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.
AnalizadaAlta (8.8)0.45%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaMedia (6.5)0.49%—Zoom Meeting Software Development KITZoom Workplace11/3/202517/6/2026
Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.25%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.24%—Mediatek Software Development KITOpenwrt3/3/202517/6/2026
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.