Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
AnalizadaMedia (6.7)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/11/202517/6/2026
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.
AnalizadaAlta (7.5)0.41%—Linuxfoundation Pytorch25/9/202517/6/2026
An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
AnalizadaAlta (7.5)0.45%—Linuxfoundation Pytorch25/9/202517/6/2026
A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
AnalizadaAlta (7.5)0.41%—Linuxfoundation Pytorch25/9/202517/6/2026
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
AnalizadaMedia (5.3)0.32%—Linuxfoundation Pytorch25/9/202517/6/2026
pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
AnalizadaAlta (7.5)0.41%—Linuxfoundation Pytorch25/9/202517/6/2026
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
AnalizadaAlta (7.5)0.42%—Linuxfoundation Pytorch25/9/202517/6/2026
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
AnalizadaAlta (7.5)0.42%—Linuxfoundation Pytorch25/9/202517/6/2026
An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
AnalizadaMedia (5.3)0.42%—Linuxfoundation Pytorch25/9/202517/6/2026
PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
AnalizadaMedia (5.3)0.45%—Linuxfoundation Pytorch25/9/202517/6/2026
In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
AnalizadaMedia (5.3)0.39%—Linuxfoundation Pytorch25/9/202517/6/2026
In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
AnalizadaMedia (5.3)0.36%—Linuxfoundation Pytorch25/9/202517/6/2026
In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
AnalizadaMedia (5.3)0.40%—Linuxfoundation Pytorch25/9/202517/6/2026
In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
AnalizadaMedia (5.5)0.14%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the network request so…
AnalizadaMedia (5.5)0.16%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding hash. This vulnerability is fixed in…
AnalizadaAlta (7.7)0.23%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC service does not validate if the requested…
AnalizadaMedia (6.9)0.73%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipient peer to create files in arbitrary file system locations, and to read arbitrary files. This allows peers to steal other peers’ secret…
AnalizadaBaja (2.7)0.31%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability is fixed in 2.1.0.
AnalizadaBaja (2.7)0.34%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An attacker may try to guess the password one character at a time by sending all…
AnalizadaBaja (2)0.11%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses the os.MkdirAll function to create certain directory paths with specific access permissions. This function does not perform any permission checks when a given directory path already exists. This…
AnalizadaMedia (5.5)0.36%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic field, because an uninitialized variable n is used as a guard to the AddTraffic method call, instead of the result.Size variable. A task…
AnalizadaBaja (2.7)0.17%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable the verification. A Manager processes dozens of preheat jobs. An adversary…
AnalizadaMedia (5.5)0.25%—Linuxfoundation Dragonfly17/9/202517/6/2026
Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make requests to internal services that are otherwise not accessible to them. The issue arises…
Orbitaley — Vulnerabilidades