Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1540 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.11%—Zephyr Ext2 Filesystem DriverAI25/8/202626/8/2026
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) treats its argument as a number of bits and reads one bitmap byte per…
Pendiente de análisisMedia (6.8)0.18%—Zephyr Ext2 Filesystem DriverAI25/8/202628/9/2026
The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group counts, but never bounds s_log_block_size. On a successful verify,…
Pendiente de análisisMedia (6.4)0.11%—Zephyr RtosAINXP Mailbox DriverAI24/8/202626/8/2026
The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to z_impl_mbox_send() and the underlying driver.…
Pendiente de análisisMedia (5.3)0.25%—Infineon Airoc Wifi DriverAI22/8/202626/8/2026
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but…
Pendiente de análisisAlta (8.8)0.34%—Zephyrproject Hl7800 Modem DriverAI19/8/202626/8/2026
The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device. The response is linearized into a…
Pendiente de análisisAlta (8.8)0.15%—Dell Watchdog Timer DriverAI18/8/202620/8/2026
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
AplazadaAlta (8.1)0.47%—Theme Test DriveAI18/8/202620/8/2026
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
Pendiente de análisisAlta (8.9)0.45%—Faye Websocket-driverAI17/8/202610/9/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does…
Pendiente de análisisMedia (5.7)0.11%—Elan Trackpoint DriverAI13/8/202624/8/2026
ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.
AplazadaAlta (7.1)0.25%—Local Delivery Drivers FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
AnalizadaAlta (8.4)0.21%—Mongodb BI Connector Odbc Driver12/8/202611/9/2026
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when…
AnalizadaAlta (8.8)0.50%—Mongodb BI Connector Odbc Driver12/8/202611/9/2026
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination,…
AnalizadaAlta (8.8)0.40%—Mongodb BI Connector Odbc Driver12/8/202611/9/2026
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to…
AnalizadaCrítica (9.5)0.54%—Mongodb BI Connector Odbc Driver12/8/202611/9/2026
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and,…
AnalizadaAlta (7.1)0.32%—Mongodb BI Connector Odbc Driver12/8/202611/9/2026
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user…
AnalizadaMedia (6.3)0.20%—Mongodb Odbc DriverMongodb SQL Schema Builder CLI12/8/202629/9/2026
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to…
Pendiente de análisisMedia (6.1)0.15%—Intel ALH Digital Audio Interface DriverAIZephyrproject ZephyrAI12/8/202626/8/2026
The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const uint8_t alh_handshake_map[64] array and scales a FIFO register address, so an out-of-range stream_id…
AnalizadaAlta (8.2)0.14%—Mongodb Java Driver11/8/202625/9/2026
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A…
AnalizadaMedia (6.7)0.39%—Microsoft Onedrive11/8/202617/8/2026
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Pendiente de análisisMedia (5.6)0.15%—AMD Ryzen Master Utility DriverAI11/8/202612/8/2026
A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability
AnalizadaMedia (6.9)0.10%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local…
AnalizadaMedia (6.9)0.13%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
AnalizadaMedia (6.9)0.10%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access…
AnalizadaMedia (5.8)0.07%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (6.9)0.13%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack…
Orbitaley — Vulnerabilidades