Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.4) | 0.17% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 8/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+2 | 8/9/2026 | 10/9/2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon EFS CSI DriverAI | 4/9/2026 | 8/9/2026 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Snowflake Jdbc DriverAI | 4/9/2026 | 10/9/2026 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI | 4/9/2026 | 10/9/2026 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle… | |
| Analizada | Media (6.9) | 0.20% | — | Mongodb PHP Driver | 3/9/2026 | 10/9/2026 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited… | |
| Analizada | Media (5.9) | 0.12% | — | Mongodb C++ Driver | 3/9/2026 | 10/9/2026 | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer… | |
| Analizada | Media (6.3) | 0.27% | — | Mongodb C Driver | 3/9/2026 | 10/9/2026 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the… | |
| Analizada | Media (5.9) | 0.14% | — | Mongodb C++ Driver | 3/9/2026 | 22/9/2026 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate… | |
| Analizada | Media (5.9) | 0.13% | — | Mongodb C Driver | 3/9/2026 | 22/9/2026 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an… | |
| Analizada | Alta (8.2) | 0.26% | — | Mongodb C Driver | 3/9/2026 | 22/9/2026 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the… | |
| Analizada | Media (6.3) | 0.31% | — | Mongodb C Driver | 3/9/2026 | 22/9/2026 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can… | |
| Pendiente de análisis | Media (6.4) | 0.23% | — | AMD Kernel Mode DriverAI | 31/8/2026 | 3/9/2026 | Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution. | |
| Analizada | Media (6) | 0.37% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying… | |
| Analizada | Alta (8.7) | 0.49% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that… | |
| Analizada | Media (6.8) | 0.09% | — | Mongodb C# Driver | 27/8/2026 | 29/9/2026 | A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret… | |
| Analizada | Alta (7.1) | 0.29% | — | Mongodb C# Driver | 27/8/2026 | 29/9/2026 | Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without… | |
| Analizada | Media (5.3) | 0.28% | — | Mongodb C# Driver | 27/8/2026 | 29/9/2026 | A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language special elements. An application that passes untrusted, loosely-typed input as a… | |
| Analizada | Media (6.9) | 0.31% | — | Mongodb C# Driver | 27/8/2026 | 29/9/2026 | A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those values are not… | |
| Analizada | Alta (7.1) | 0.36% | — | Mongodb Rust Driver | 27/8/2026 | 29/9/2026 | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same… | |
| Analizada | Alta (8.6) | 0.49% | — | Mongodb PHP DriverMongodb PHP Library | 27/8/2026 | 29/9/2026 | The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a… | |
| Analizada | Media (5.3) | 0.27% | — | Mongodb C Driver | 27/8/2026 | 29/9/2026 | A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at… | |
| Analizada | Alta (8.6) | 0.46% | — | Mongodb C++ Driver | 27/8/2026 | 29/9/2026 | A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended.… | |
| Analizada | Alta (7.1) | 0.36% | — | Mongodb GO Driver | 27/8/2026 | 6/10/2026 | The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have… | |
| Pendiente de análisis | Crítica (9.4) | 0.45% | — | Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI | 26/8/2026 | 31/8/2026 | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project… |