Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.76%—Nanohttpd23/2/202117/6/2026
An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to reflected XSS, because the GeneralHandler…
ModificadaAlta (7.2)4.5%—Netshieldcorp Nano 25 Firmware22/2/202117/6/2026
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.
ModificadaCrítica (9.8)1.5%—Nanorand Project Nanorand31/12/202017/6/2026
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
ModificadaAlta (7.5)2.7%—Nanopb Project Nanopb25/11/202017/6/2026
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static submessage that contains a dynamic field, and the message being decoded contains the…
ModificadaCrítica (9.8)1.3%—Nanometrics CentaurNanometrics Titansma24/4/202017/6/2026
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
ModificadaCrítica (9.8)1.7%—Nanopb Project Nanopb4/2/202017/6/2026
There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLOC, the message to be decoded contains a repeated string, bytes or message field and realloc() runs out of memory when expanding the array nanopb can end up calling…
ModificadaBaja (2.4)0.35%—Ledger Nano S FirmwareLedger Nano X Firmware10/8/201917/6/2026
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage…
ModificadaMedia (6.5)1.8%—Nanosvg Project Nanosvg15/5/201917/6/2026
nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726 is affected by: Buffer Overflow. The impact is: Memory corruption leading to at least DoS. More severe impact vectors need more investigation. The component is: it's part of a svg processing library. function nsvg__parseColorRGB in…
ModificadaMedia (5.9)0.53%—HP 310s-14isk FirmwareHP 320-15ikbra FirmwareHP 320-15ikbrn FirmwareHP 320-15ikbrn Touch Firmware+642/10/201817/6/2026
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
ModificadaAlta (7.5)77%💥 ExploitNanopool Claymore Dual Miner9/2/201817/6/2026
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.
ModificadaMedia (5.4)0.27%—Magzter Nano Digest21/10/201417/6/2026
The Nano Digest (aka com.magzter.nanodigest) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.8)2.2%—Triplc Nano-10 PLC FirmwareTriplc Nano-10 PLC29/10/201316/6/2026
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large length values in MODBUS data, which allows remote attackers to cause a denial of service (transition to the interrupt state) via a crafted packet to TCP port 502.
ModificadaAlta (7.8)4.0%💥 ExploitTriplc Nano-10 PLC FirmwareTriplc Nano-10 PLC10/7/201316/6/2026
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote attackers to cause a denial of service (networking outage) via a crafted packet to TCP port 502.
ModificadaMedia (5)3.0%💥 ExploitEnanocms Enano CMS7/4/201116/6/2026
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.
ModificadaAlta (7.5)1.6%💥 ExploitEnanocms Enano CMS7/4/201116/6/2026
SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained…
ModificadaBaja (3.7)0.28%—GNU Nano16/4/201016/6/2026
Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.
ModificadaBaja (1.9)0.37%—GNU Nano16/4/201016/6/2026
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.
ModificadaMedia (6.8)3.4%—Nanosleep Trac-git10/2/201016/6/2026
PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.
ModificadaAlta (7.5)1.1%—Enanocms2/2/201016/6/2026
SQL injection vulnerability in the comment submission interface (includes/comment.php) in Enano CMS before 1.0.6pl1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
ModificadaMedia (5)1.8%—Nanoblogger19/6/200516/6/2026
Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.
ModificadaAlta (10)2.8%—Ehud Gavron Traceroute-nanog7/8/200316/6/2026
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.
Orbitaley — Vulnerabilidades