Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.64% | — | Mediatek Mt7902 FirmwareMediatek Mt7921 FirmwareMediatek Mt7922 FirmwareMediatek Mt7925 Firmware+1 | 2/6/2025 | 17/6/2026 | In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292. | |
| Modificada | Media (5.7) | 0.33% | — | Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 5/5/2025 | 17/6/2026 | In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01334347;… | |
| Modificada | Alta (7.5) | 0.45% | — | Mediatek Lr12aMediatek Lr13Mediatek Nr15Mediatek Nr16+2 | 5/5/2025 | 17/6/2026 | In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Modificada | Alta (7.5) | 0.83% | — | Mediatek Nr15 | 5/5/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00650610; Issue… | |
| Analizada | Alta (7.5) | 0.54% | — | Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+3 | 7/4/2025 | 17/6/2026 | In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406217; Issue ID: MSV-2773. | |
| Analizada | Alta (7.5) | 0.54% | — | Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+1 | 7/4/2025 | 17/6/2026 | In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00408868; Issue ID: MSV-3031. | |
| Analizada | Media (6.7) | 0.08% | — | Google AndroidMediatek Mt9972 | 7/4/2025 | 17/6/2026 | In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04428276; Issue ID: MSV-3184. | |
| Analizada | Media (6.7) | 0.08% | — | Google AndroidMediatek Mt9972 | 7/4/2025 | 17/6/2026 | In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04436357; Issue ID: MSV-3185. | |
| Modificada | Media (6.5) | 0.36% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+81 | 7/4/2025 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028;… | |
| Analizada | Media (6) | 0.11% | — | Google AndroidMediatek Mt2718Mediatek Mt6781Mediatek Mt6789+15 | 7/4/2025 | 17/6/2026 | In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597. | |
| Analizada | Media (6.8) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+16 | 7/4/2025 | 17/6/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033. | |
| Analizada | Media (5.3) | 0.08% | — | Google AndroidMediatek Mt9972 | 7/4/2025 | 17/6/2026 | In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID: MSV-3183. | |
| Analizada | Crítica (9.8) | 0.81% | — | Mediatek Software Development KITMediatek Mt7622Mediatek Mt7915Mediatek Mt7916+4 | 7/4/2025 | 17/6/2026 | In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875. | |
| Analizada | Media (6.5) | 0.24% | — | Mediatek Software Development KITOpenwrt | 3/3/2025 | 17/6/2026 | In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184. | |
| Modificada | Media (6.5) | 0.36% | — | Mediatek Nr12aMediatek Nr13Mediatek Nr15Mediatek Nr16 | 3/3/2025 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00791311 /… | |
| Analizada | Crítica (9.8) | 0.88% | — | Mediatek Software Development KIT | 3/3/2025 | 17/6/2026 | In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803. | |
| Modificada | Media (6.5) | 0.38% | — | Mediatek Nr15Mediatek Nr16 | 3/3/2025 | 17/6/2026 | In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Modificada | Alta (7.5) | 0.64% | — | Mediatek Software Development KIT | 3/2/2025 | 17/6/2026 | In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00399035; Issue ID: MSV-2380. | |
| Modificada | Crítica (9.8) | 0.77% | — | Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 3/2/2025 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01289384;… | |
| Modificada | Alta (8.8) | 0.33% | — | Mediatek Software Development KIT | 3/2/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491. | |
| Analizada | Alta (7.8) | 0.18% | — | Mediatek Software Development KIT | 3/2/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397139; Issue ID: MSV-2188. | |
| Analizada | Alta (7.8) | 0.18% | — | Mediatek Software Development KIT | 3/2/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397141; Issue ID: MSV-2187. | |
| Analizada | Media (5.3) | 0.21% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 3/2/2025 | 17/6/2026 | In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737,… | |
| Modificada | Alta (8.8) | 3.9% | 💥 PoC | Mediatek Lr12aMediatek Lr13Mediatek Nr16.r1.mpMediatek Nr16.r1.mp1mp2.mp+1 | 6/1/2025 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348;… | |
| Analizada | Alta (7.5) | 0.32% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle Android | 6/1/2025 | 17/6/2026 | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598. |