Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.21% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification.… | |
| Aplazada | Alta (7.1) | 0.22% | — | Dylan James Zephyr Project ManagerAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201. | |
| Analizada | Media (6.8) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 4/8/2025 | 17/6/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801. | |
| Analizada | Alta (7.5) | 0.57% | — | Zephyrproject Zephyr | 24/6/2025 | 17/6/2026 | A denial-of-service issue in the dns implemenation could cause an infinite loop. | |
| Analizada | Media (4.8) | 0.27% | — | Zephyrwest Category Posts Widget | 24/4/2025 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 0.31% | — | Zephyr-one Zephyr Project Manager | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through <= 3.3.101. | |
| Aplazada | Media (5.4) | 0.35% | — | Dylan James Zephyr Project ManagerAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.200. | |
| Analizada | Crítica (9.1) | 0.39% | — | Zephyrproject Zephyr | 25/2/2025 | 17/6/2026 | The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is large enough to contain the copied data. | |
| Analizada | Alta (8.2) | 0.37% | — | Zephyrproject Zephyr | 25/2/2025 | 17/6/2026 | A lack of input validation allows for out of bounds reads caused by malicious or malformed packets. | |
| Analizada | Alta (8.2) | 0.35% | — | Zephyrproject Zephyr | 25/2/2025 | 17/6/2026 | A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation. | |
| Analizada | Alta (7.5) | 0.31% | — | Zephyrproject Zephyr | 3/2/2025 | 17/6/2026 | No proper validation of the length of user input in http_server_get_content_type_from_extension. | |
| Aplazada | Alta (7.1) | 0.15% | — | Dylan James Zephyr Modern Admin ThemeAI | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross Site Request Forgery.This issue affects Zephyr Admin Theme: from n/a through <= 1.4.1. | |
| Analizada | Media (4.8) | 0.37% | — | Zephyrwest Category Posts Widget | 7/1/2025 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.5) | 0.42% | — | Zephyrproject Zephyr | 16/12/2024 | 17/6/2026 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. | |
| Analizada | Alta (8.4) | 0.17% | — | Zephyrproject Zephyr | 15/11/2024 | 17/6/2026 | When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols. | |
| Analizada | Media (6.5) | 0.34% | — | Zephyrproject Zephyr | 4/10/2024 | 17/6/2026 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. | |
| Analizada | Media (6.5) | 0.61% | — | Zephyrproject Zephyr | 4/10/2024 | 17/6/2026 | In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty. | |
| Analizada | Media (6.5) | 0.34% | — | Zephyrproject Zephyr | 4/10/2024 | 17/6/2026 | In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. | |
| Modificada | Media (6.5) | 0.61% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT: HCI: adv_ext_report Improper discarding in adv_ext_report | |
| Modificada | Media (6.5) | 0.55% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT: Classic: SDP OOB access in get_att_search_list | |
| Analizada | Media (6.5) | 0.44% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT:Classic: Multiple missing buf length checks | |
| Modificada | Media (6.5) | 0.45% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT: Unchecked user input in bap_broadcast_assistant | |
| Modificada | Media (6.5) | 0.43% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT: Missing length checks of net_buf in rfcomm_handle_data | |
| Modificada | Media (6.5) | 0.31% | — | Zephyrproject Zephyr | 13/9/2024 | 17/6/2026 | BT: Encryption procedure host vulnerability | |
| Analizada | Alta (7.1) | 0.32% | — | Dylanjkotze Zephyr Project Manager | 26/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102. |