Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1271 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.9) | 0.45% | — | Faye Websocket-driverAI | 17/8/2026 | 10/9/2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does… | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Elan Trackpoint DriverAI | 13/8/2026 | 24/8/2026 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash. | |
| Aplazada | Alta (7.1) | 0.25% | — | Local Delivery Drivers FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | |
| Analizada | Alta (8.4) | 0.21% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when… | |
| Analizada | Alta (8.8) | 0.50% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination,… | |
| Analizada | Alta (8.8) | 0.40% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to… | |
| Analizada | Crítica (9.5) | 0.54% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and,… | |
| Analizada | Alta (7.1) | 0.32% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user… | |
| Analizada | Media (6.3) | 0.20% | — | Mongodb Odbc DriverMongodb SQL Schema Builder CLI | 12/8/2026 | 29/9/2026 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Intel ALH Digital Audio Interface DriverAIZephyrproject ZephyrAI | 12/8/2026 | 26/8/2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const uint8_t alh_handshake_map[64] array and scales a FIFO register address, so an out-of-range stream_id… | |
| Analizada | Alta (8.2) | 0.14% | — | Mongodb Java Driver | 11/8/2026 | 25/9/2026 | A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A… | |
| Pendiente de análisis | Media (5.6) | 0.15% | — | AMD Ryzen Master Utility DriverAI | 11/8/2026 | 12/8/2026 | A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (6.9) | 0.13% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access… | |
| Analizada | Media (5.8) | 0.07% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 28/9/2026 | Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.9) | 0.13% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 28/9/2026 | Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.9) | 0.25% | — | Realtek BEE Bluetooth HCI DriverAI | 11/8/2026 | 26/8/2026 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and… | |
| Analizada | Alta (7.8) | 0.16% | — | Dell Monitor Driver | 3/8/2026 | 7/8/2026 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Media (6.1) | 0.11% | — | Libfsimage Iso9660 DriverAI | 28/7/2026 | 28/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Pendiente de análisis | Alta (8.8) | 1.3% | — | LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI | 24/7/2026 | 30/7/2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a… | |
| Aplazada | Media (6.3) | 0.45% | — | Websocket DriverAI | 17/7/2026 | 23/7/2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size because the limit is checked against the message… | |
| Analizada | Crítica (9.2) | 0.38% | — | Faye Websocket-driver | 17/7/2026 | 6/8/2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with… | |
| Analizada | Media (6.3) | 0.49% | — | Faye Websocket-driver | 17/7/2026 | 6/8/2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by… | |
| Analizada | Media (6.9) | 0.49% | — | Faye Websocket-driver | 17/7/2026 | 6/8/2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80… |