Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.14%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt6/1/202517/6/2026
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
AnalizadaMedia (4.6)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
AnalizadaAlta (8.8)0.30%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
AnalizadaMedia (6.2)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
AnalizadaMedia (6.5)0.36%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
AnalizadaAlta (8.8)0.46%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
ModificadaAlta (8.8)0.31%—Autodesk FBX Software Development KIT9/12/202417/6/2026
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
AnalizadaMedia (6.5)0.12%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt2/12/202417/6/2026
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
AnalizadaAlta (7.5)0.29%—Mediatek Software Development KITGoogle Android2/12/202417/6/2026
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
AnalizadaAlta (7.5)0.55%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.47%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.50%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+319/11/202417/6/2026
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (7.3)0.24%—AMD Ryzen Master Monitoring Software Development KIT12/11/202417/6/2026
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaCrítica (9.8)0.33%—Mediatek Software Development KITGoogle Android7/10/202417/6/2026
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.
AnalizadaCrítica (9.8)0.32%—Mediatek Software Development KITGoogle Android7/10/202417/6/2026
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.
AnalizadaCrítica (9.8)0.33%—Mediatek IOT YoctoMediatek Software Development KITGoogle Android7/10/202417/6/2026
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
ModificadaMedia (6.7)0.24%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.7)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.18%—Zoom Meeting Software Development KITZoom Workplace Desktop14/8/202417/6/2026
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Orbitaley — Vulnerabilidades