Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.27%—Zephyrproject Zephyr15/6/20266/8/2026
Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback and re-acquired it…
AnalizadaAlta (8.8)0.32%—Zephyrproject Zephyr9/6/202623/7/2026
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size smaller than 2 bytes, the segmentation counter stored in the net_buf…
AnalizadaCrítica (9.8)0.86%—Zephyrproject Zephyr9/6/202623/7/2026
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when the input length reaches…
AnalizadaAlta (8.8)0.47%—Zephyrproject Zephyr4/6/202622/7/2026
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). When the TLS session cache is enabled, tls_session_store() and tls_session_restore() memcpy the caller-supplied address into a fixed-size buffer using the…
AnalizadaMedia (6.3)0.36%—Zephyrproject Zephyr4/6/202622/7/2026
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is enabled, the function parses solicitation PDUs from raw BLE advertising payloads. The AD parsing loop reads an…
AnalizadaAlta (7.8)0.17%—Zephyrproject Zephyr30/5/202622/7/2026
The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where assertions are disabled, a userspace application that controls the…
AnalizadaMedia (6.5)0.32%—Zephyrproject Zephyr22/5/202623/7/2026
A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to set an unvalidated negative log_announce_interval value in the port's data set. When a subsequent PTP_MSG_ANNOUNCE message…
AnalizadaMedia (6.1)0.14%—Zephyrproject Zephyr12/5/20268/7/2026
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply are processed inline…
AnalizadaMedia (5.3)0.24%—Zephyrproject Zephyr11/5/20268/7/2026
Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version`). The ClientHello advertises both versions and the peer can…
AnalizadaMedia (5.3)0.27%—Zephyrproject Zephyr5/4/202624/7/2026
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading…
AnalizadaAlta (7.8)0.21%—Zephyrproject Zephyr28/3/202617/6/2026
The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploit requires local code that can call the socket send API; no remote attacker can reach it directly.
AnalizadaMedia (6.1)0.15%—Zephyrproject Zephyr16/3/202617/6/2026
Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
AnalizadaMedia (6.8)0.24%—Zephyrproject Zephyr16/3/202617/6/2026
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.
AnalizadaCrítica (9.8)0.39%—Zephyrproject Zephyr5/3/202617/6/2026
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when…
AnalizadaMedia (4.6)0.12%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+12/3/202617/6/2026
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID:…
AplazadaMedia (6.5)0.34%—Zephyrproject ZephyrAI30/1/202617/6/2026
A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.
AplazadaMedia (4.9)0.69%—Zephyr Project ManagerAI17/12/202528/9/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain…
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
AplazadaMedia (4.4)0.20%—Zephyr Project ManagerAI26/9/202517/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AnalizadaMedia (6.5)0.21%—Zephyrproject Zephyr19/9/202517/6/2026
Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabling precise memory corruption.
AnalizadaAlta (7.6)0.21%—Zephyrproject Zephyr19/9/202517/6/2026
Parameters are not validated or sanitized, and are later used in various internal operations.
AnalizadaAlta (8.1)0.40%—Zephyrproject Zephyr19/9/202517/6/2026
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.
AnalizadaMedia (6.5)0.21%—Zephyrproject Zephyr19/9/202517/6/2026
A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification.…
AplazadaAlta (7.1)0.22%—Dylan James Zephyr Project ManagerAI28/8/202525/9/2026
Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.
Orbitaley — Vulnerabilidades