Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
484 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.60% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan(). | |
| Analizada | Crítica (9.8) | 0.48% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d. | |
| Analizada | Crítica (9.8) | 0.70% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_. | |
| Analizada | Crítica (9.8) | 0.48% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller. | |
| Analizada | Crítica (9.8) | 0.70% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller. | |
| Analizada | Crítica (9.8) | 0.70% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller. | |
| Analizada | Crítica (9.8) | 0.70% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl. | |
| Analizada | Crítica (9.8) | 0.70% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component. | |
| Analizada | Crítica (9.8) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`. | |
| Analizada | Crítica (9.8) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`. | |
| Analizada | Crítica (9.8) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` . | |
| Analizada | Crítica (9.8) | 0.55% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` . | |
| Analizada | Crítica (9.8) | 0.55% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` . | |
| Analizada | Crítica (9.8) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose. | |
| Analizada | Crítica (9.8) | 0.60% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` . | |
| Aplazada | Alta (7.3) | 0.31% | — | Open Robotic Operating System Ros2AIOpen Robotic Operating System Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process | |
| Aplazada | Alta (7.8) | 0.22% | — | Openrobotics Robotic Operating System 2AIOpenrobotics Navigation2AI | 5/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator | |
| Aplazada | Alta (7.8) | 0.23% | — | Openrobotics Robotic Operating System 2AIOpenrobotics Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script. | |
| Modificada | Alta (7.8) | 0.29% | — | Openrobotics Robot Operating System | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process | |
| Analizada | Alta (7.8) | 0.29% | — | Openrobotics Robot Operating System | 5/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator. | |
| Analizada | Alta (8.5) | 0.62% | — | Broadcom Fabric Operating System | 21/11/2024 | 17/6/2026 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade… | |
| Analizada | Media (5.9) | 0.65% | — | Broadcom Fabric Operating System | 21/11/2024 | 17/6/2026 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave. | |
| Analizada | Alta (7) | 0.25% | — | Broadcom Fabric Operating System | 12/11/2024 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin. | |
| Analizada | Media (6.5) | 0.28% | — | Dell Data Domain Operating System | 8/11/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (7.2) | 0.38% | — | Dell Data Domain Operating System | 8/11/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privilege on the application. |