Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

1271 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.12%—Mongodb C++ Driver3/9/202610/9/2026
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer…
AnalizadaMedia (6.3)0.27%—Mongodb C Driver3/9/202610/9/2026
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the…
AnalizadaMedia (5.9)0.14%—Mongodb C++ Driver3/9/202622/9/2026
An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate…
AnalizadaMedia (5.9)0.13%—Mongodb C Driver3/9/202622/9/2026
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an…
AnalizadaAlta (8.2)0.26%—Mongodb C Driver3/9/202622/9/2026
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the…
AnalizadaMedia (6.3)0.31%—Mongodb C Driver3/9/202622/9/2026
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can…
Pendiente de análisisMedia (6.4)0.23%—AMD Kernel Mode DriverAI31/8/20263/9/2026
Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.
AnalizadaMedia (6)0.37%—Mongodb BI Connector Odbc Driver28/8/202611/9/2026
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying…
AnalizadaAlta (8.7)0.49%—Mongodb BI Connector Odbc Driver28/8/202611/9/2026
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that…
AnalizadaMedia (6.8)0.09%—Mongodb C# Driver27/8/202629/9/2026
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret…
AnalizadaAlta (7.1)0.29%—Mongodb C# Driver27/8/202629/9/2026
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without…
AnalizadaMedia (5.3)0.28%—Mongodb C# Driver27/8/202629/9/2026
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language special elements. An application that passes untrusted, loosely-typed input as a…
AnalizadaMedia (6.9)0.31%—Mongodb C# Driver27/8/202629/9/2026
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those values are not…
AnalizadaAlta (7.1)0.36%—Mongodb Rust Driver27/8/202629/9/2026
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same…
AnalizadaAlta (8.6)0.49%—Mongodb PHP DriverMongodb PHP Library27/8/202629/9/2026
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a…
AnalizadaMedia (5.3)0.27%—Mongodb C Driver27/8/202629/9/2026
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at…
AnalizadaAlta (8.6)0.46%—Mongodb C++ Driver27/8/202629/9/2026
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended.…
AnalizadaAlta (7.1)0.36%—Mongodb GO Driver27/8/20266/10/2026
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have…
Pendiente de análisisCrítica (9.4)0.45%—Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI26/8/202631/8/2026
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project…
Pendiente de análisisMedia (5.5)0.11%—Zephyr Ext2 Filesystem DriverAI25/8/202626/8/2026
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) treats its argument as a number of bits and reads one bitmap byte per…
Pendiente de análisisMedia (6.8)0.18%—Zephyr Ext2 Filesystem DriverAI25/8/202628/9/2026
The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group counts, but never bounds s_log_block_size. On a successful verify,…
Pendiente de análisisMedia (6.4)0.11%—Zephyr RtosAINXP Mailbox DriverAI24/8/202626/8/2026
The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to z_impl_mbox_send() and the underlying driver.…
Pendiente de análisisMedia (5.3)0.25%—Infineon Airoc Wifi DriverAI22/8/202626/8/2026
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but…
Pendiente de análisisAlta (8.8)0.34%—Zephyrproject Hl7800 Modem DriverAI19/8/202626/8/2026
The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device. The response is linearized into a…
Pendiente de análisisAlta (8.8)0.15%—Dell Watchdog Timer DriverAI18/8/202620/8/2026
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Orbitaley — Vulnerabilidades