Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.73% | — | Emqx Nanomq | 4/5/2023 | 17/6/2026 | In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c. | |
| Modificada | Crítica (9.8) | 1.2% | — | Nanoleaf Firmware | 27/4/2023 | 9/7/2026 | Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. | |
| Modificada | Crítica (9.8) | 1.9% | — | Nanoleaf Desktop | 18/4/2023 | 9/7/2026 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Crítica (9.1) | 0.85% | — | Digitalocean Golang-nanoauth | 27/12/2022 | 17/6/2026 | Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token. | |
| Modificada | Crítica (9.8) | 0.59% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+13 | 26/7/2022 | 17/6/2026 | JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of… | |
| Modificada | Crítica (9.1) | 1.3% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+13 | 26/7/2022 | 17/6/2026 | JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This… | |
| Modificada | Media (5.5) | 0.30% | — | Nanohttpd | 1/5/2022 | 17/6/2026 | This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP request, the body of the request is written to a RandomAccessFile when the it is larger than 1024 bytes. This file is created with insecure permissions that allow its contents to be viewed by all users… | |
| Modificada | Media (5.5) | 0.44% | — | Nanoid Project Nanoid | 14/1/2022 | 17/6/2026 | The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. | |
| Modificada | Crítica (9.8) | 1.2% | — | Nanorand Project Nanorand | 27/12/2021 | 17/6/2026 | An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure. | |
| Modificada | Media (4.1) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure. | |
| Modificada | Alta (7.5) | 0.31% | — | Nvidia Geforce GT 605Nvidia Geforce GT 610Nvidia Geforce GT 620Nvidia Geforce GT 625+59 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact… | |
| Modificada | Alta (7.5) | 0.28% | — | Nvidia Geforce GTX 950Nvidia Geforce GTX 960Nvidia Geforce GTX 970Nvidia Geforce GTX 980+31 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of… | |
| Modificada | Media (4.4) | 0.20% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+103 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure. | |
| Modificada | Media (5.5) | 0.23% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. | |
| Modificada | Media (6.7) | 0.29% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.3) | 0.41% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+23 | 10/9/2021 | 17/6/2026 | All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices. | |
| Modificada | Alta (7.5) | 1.1% | — | Jtekt Pc10g-cpu FirmwareJtekt 2port-efr FirmwareJtekt Plus CPU FirmwareJtekt Plus EX Firmware+18 | 1/7/2021 | 17/6/2026 | When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a… | |
| Modificada | Media (4.2) | 0.41% | — | NXP Mifare Ultralight EV1 FirmwareNXP Mifare Ultralight C FirmwareNXP Mifare Ultralight Nano FirmwareNXP Ntag 210 Firmware+4 | 6/6/2021 | 17/6/2026 | On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access… | |
| Modificada | Alta (7.1) | 1.8% | 💥 PoC | Nanopb Project Nanopb | 23/3/2021 | 17/6/2026 | Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message type contains an `oneof` field, and the `oneof` directly contains both a pointer field and a… | |
| Modificada | Crítica (9.8) | 1.5% | — | Nano Arena Project Nano Arena | 5/3/2021 | 17/6/2026 | An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at because two mutable references can exist for the same element, if Borrow<Idx> behaves in certain ways. This can have a resultant out-of-bounds write or use-after-free. |