Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.46% | — | Mongodb Java Driver | 10/9/2026 | 16/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Alta (8.2) | 0.26% | — | Mongodb Java Driver | 10/9/2026 | 16/9/2026 | A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application… | |
| Pendiente de análisis | Alta (7) | 0.17% | — | Silabs Cp210x DriverAI | 10/9/2026 | 10/9/2026 | In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges. | |
| Pendiente de análisis | Baja (2.4) | 0.15% | — | Silabs Cp210x DriverAI | 10/9/2026 | 10/9/2026 | In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier. | |
| Pendiente de análisis | Media (6.9) | 0.13% | — | Microsoft Windows 8AISilabs Cp210x DriverAI | 10/9/2026 | 10/9/2026 | In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. | |
| Analizada | Media (6.1) | 0.48% | — | Mongodb GO Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Media (6.1) | 0.48% | — | Mongodb Ruby Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Media (6.1) | 0.27% | — | Mongodb Python Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Alta (7.1) | 0.38% | — | Mongodb C# Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected application. An authenticated user who can influence such a value may cause the… | |
| Analizada | Media (6.1) | 0.48% | — | Mongodb C# Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Media (6.1) | 0.48% | — | Mongodb Rust Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file. | |
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered… | |
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation. | |
| Analizada | Media (6.3) | 0.10% | — | Okta Hyperdrive | 8/9/2026 | 23/9/2026 | The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process… | |
| Pendiente de análisis | Alta (8.2) | 0.51% | — | Snowflake DriversAI | 8/9/2026 | 10/9/2026 | In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and… | |
| Pendiente de análisis | Alta (7.7) | 0.13% | — | ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI | 8/9/2026 | 10/9/2026 | A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to cause a denial of service or disclose sensitive information. This… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU processing operations to access already freed memory. This issue affects Valhall GPU Kernel Driver: from r50p0 through r54p3, r55p0; Arm… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (4) | 0.11% | — | ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | ARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Valhall GPU Userspace Driver:… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue… |