Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.26%—Zephyr-one Zephyr Project Manager26/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
ModificadaMedia (6.5)0.46%—Zephyrproject Zephyr19/8/202417/6/2026
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
AnalizadaCrítica (9.8)0.37%—Zephyr-one Zephyr Project Manager18/8/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
AnalizadaAlta (8.1)0.40%—Zephyr-one Zephyr Project Manager15/8/202417/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function.…
AnalizadaMedia (4.8)0.44%—Tiptoppress Term AND Category Based Posts WidgetZephyrwest Category Posts Widget12/8/202417/6/2026
The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as…
AnalizadaMedia (5.4)0.33%—Zephyr-one Zephyr Project Manager3/8/202417/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
AnalizadaAlta (7.5)0.45%—Zephyr-one Zephyr Project Manager1/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
AnalizadaMedia (5.4)0.77%💥 PoCDylanjkotze Zephyr Project Manager30/7/202417/6/2026
The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaAlta (8.8)0.44%—Zephyr-one Zephyr Project Manager9/7/202417/6/2026
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
AnalizadaMedia (6.5)0.45%—Zephyrproject Zephyr3/7/202417/6/2026
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
AnalizadaMedia (6.5)0.47%—Zephyrproject Zephyr29/3/202417/6/2026
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
ModificadaAlta (7.5)0.49%—Zephyrproject Zephyr15/3/202417/6/2026
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address.
AnalizadaCrítica (9.8)0.44%—Zephyrproject Zephyr29/2/202417/6/2026
Possible buffer overflow in is_mount_point
AnalizadaCrítica (9.1)0.35%—Zephyrproject Zephyr19/2/202417/6/2026
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined…
AnalizadaCrítica (9.8)0.44%—Zephyrproject Zephyr18/2/202417/6/2026
Signed to unsigned conversion esp32_ipm_send
AnalizadaCrítica (9.8)0.44%—Zephyrproject Zephyr18/2/202417/6/2026
can: out of bounds in remove_rx_filter function
AnalizadaCrítica (9.8)0.44%—Zephyrproject Zephyr18/2/202417/6/2026
Unchecked length coming from user input in settings shell
ModificadaMedia (6.1)0.36%—Zephyr Project Manager Project Zephyr Project Manager29/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
ModificadaCrítica (9.8)0.75%—Zephyrproject Zephyr21/11/202317/6/2026
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
ModificadaAlta (8.8)0.39%—Zephyrproject Zephyr21/11/202317/6/2026
An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, leading to DoS or potential RCE on the victim BLE device.
ModificadaAlta (7.8)0.43%—Zephyrproject Zephyr26/10/202317/6/2026
Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
ModificadaAlta (8.8)0.88%—Zephyrproject Zephyr25/10/202317/6/2026
Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c
ModificadaCrítica (9.8)0.88%—Zephyrproject Zephyr13/10/202317/6/2026
Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
ModificadaAlta (8.8)0.49%—Zephyrproject Zephyr13/10/202317/6/2026
Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver
ModificadaAlta (7.5)0.45%—Zephyrproject Zephyr13/10/202317/6/2026
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
Orbitaley — Vulnerabilidades