Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2779 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.4)0.16%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.
AnalizadaMedia (4.4)0.16%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.
AnalizadaMedia (6.7)0.17%—Mediatek Mt8910 FirmwareMediatek Mt2718 FirmwareMediatek Mt6878 FirmwareMediatek Mt6895 Firmware+73/8/202619/8/2026
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
AnalizadaMedia (6)0.16%—Mediatek Mt6993 Firmware3/8/202619/8/2026
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.
AnalizadaMedia (4.4)0.16%—Mediatek Mt8799 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+353/8/202619/8/2026
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
AnalizadaAlta (7.7)0.17%—Mediatek Mt8893 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+313/8/202619/8/2026
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
AnalizadaMedia (6.5)0.30%—Mediatek Mt8532 FirmwareMediatek Mt7902 FirmwareMediatek Mt7921 FirmwareMediatek Mt7922 Firmware+13/8/202619/8/2026
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
AnalizadaMedia (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+103/8/202619/8/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
AnalizadaMedia (5.5)0.14%—Mediatek Mt6880 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 Firmware+33/8/202619/8/2026
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For…
AnalizadaAlta (7.5)0.71%—Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+153/8/202619/8/2026
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071;…
AnalizadaMedia (5.5)0.14%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 FirmwareMediatek Mt6890 Firmware+23/8/202620/8/2026
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735,…
AnalizadaMedia (6)0.17%—Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8188 Firmware+63/8/202619/8/2026
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.
AnalizadaMedia (5.5)0.15%—Mediatek Mt6988 FirmwareMediatek Mt6813 FirmwareMediatek Mt6986 Firmware3/8/202619/8/2026
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.
AnalizadaMedia (6)0.17%—Mediatek Mt8910 FirmwareMediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+133/8/202619/8/2026
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.
AnalizadaMedia (6)0.13%—Mediatek Mt6991 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 FirmwareMediatek Mt8171 Firmware+133/8/202619/8/2026
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.
AnalizadaMedia (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8910 FirmwareMediatek Mt6993 FirmwareMediatek Mt8126 Firmware+133/8/202619/8/2026
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.
AplazadaMedia (4.6)0.23%—Mediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AIMediatek Mt6988AI+43/8/202628/8/2026
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890,…
AplazadaMedia (6.1)0.17%—Mediatek Mt2737AIMediatek Mt6880AIMediatek Mt6890AIMediatek Mt6990AI3/8/202628/8/2026
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For…
AplazadaMedia (5.4)0.13%—Najeebmedia Frontend File ManagerAI2/8/202626/8/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,…
AplazadaAlta (8.6)0.73%—WP Media Folder AddonAI29/7/202610/8/2026
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been…
AplazadaMedia (4.1)0.41%—Media CleanerAI28/7/202628/7/2026
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an insufficient hostname validation check that…
AplazadaAlta (8.5)0.36%—Rtcamp RtmediaAI27/7/202627/7/2026
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
AplazadaCrítica (9.3)0.40%—Rtcamp RtmediaAI27/7/202627/7/2026
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
AplazadaMedia (6.1)0.25%—Polen Media Software AND Information Services Website TemplateAI24/7/202624/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.
AplazadaMedia (4.3)0.25%—Mediavine Control PanelAI23/7/202623/7/2026
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.