Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.73%—Emqx Nanomq4/5/202317/6/2026
In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.
ModificadaCrítica (9.8)1.2%—Nanoleaf Firmware27/4/20239/7/2026
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
ModificadaCrítica (9.8)1.9%—Nanoleaf Desktop18/4/20239/7/2026
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+32130/1/202317/6/2026
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaCrítica (9.1)0.85%—Digitalocean Golang-nanoauth27/12/202217/6/2026
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
ModificadaCrítica (9.8)0.59%—Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+1326/7/202217/6/2026
JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of…
ModificadaCrítica (9.1)1.3%—Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+1326/7/202217/6/2026
JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This…
ModificadaMedia (5.5)0.30%—Nanohttpd1/5/202217/6/2026
This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP request, the body of the request is written to a RandomAccessFile when the it is larger than 1024 bytes. This file is created with insecure permissions that allow its contents to be viewed by all users…
ModificadaMedia (5.5)0.44%—Nanoid Project Nanoid14/1/202217/6/2026
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
ModificadaCrítica (9.8)1.2%—Nanorand Project Nanorand27/12/202117/6/2026
An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.
ModificadaMedia (4.1)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.
ModificadaAlta (7.5)0.31%—Nvidia Geforce GT 605Nvidia Geforce GT 610Nvidia Geforce GT 620Nvidia Geforce GT 625+5920/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact…
ModificadaAlta (7.5)0.28%—Nvidia Geforce GTX 950Nvidia Geforce GTX 960Nvidia Geforce GTX 970Nvidia Geforce GTX 980+3120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of…
ModificadaMedia (4.4)0.20%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+10320/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.
ModificadaMedia (5.5)0.23%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
ModificadaMedia (6.7)0.29%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (4.3)0.41%—Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+2310/9/202117/6/2026
All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.
ModificadaAlta (7.5)1.1%—Jtekt Pc10g-cpu FirmwareJtekt 2port-efr FirmwareJtekt Plus CPU FirmwareJtekt Plus EX Firmware+181/7/202117/6/2026
When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a…
ModificadaMedia (4.2)0.41%—NXP Mifare Ultralight EV1 FirmwareNXP Mifare Ultralight C FirmwareNXP Mifare Ultralight Nano FirmwareNXP Ntag 210 Firmware+46/6/202117/6/2026
On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access…
ModificadaAlta (7.1)1.8%💥 PoCNanopb Project Nanopb23/3/202117/6/2026
Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message type contains an `oneof` field, and the `oneof` directly contains both a pointer field and a…
ModificadaCrítica (9.8)1.5%—Nano Arena Project Nano Arena5/3/202117/6/2026
An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at because two mutable references can exist for the same element, if Borrow<Idx> behaves in certain ways. This can have a resultant out-of-bounds write or use-after-free.
Orbitaley — Vulnerabilidades