Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Zephyr-one Zephyr Project Manager | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102. | |
| Modificada | Media (6.5) | 0.46% | — | Zephyrproject Zephyr | 19/8/2024 | 17/6/2026 | BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero | |
| Analizada | Crítica (9.8) | 0.37% | — | Zephyr-one Zephyr Project Manager | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100. | |
| Analizada | Alta (8.1) | 0.40% | — | Zephyr-one Zephyr Project Manager | 15/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function.… | |
| Analizada | Media (4.8) | 0.44% | — | Tiptoppress Term AND Category Based Posts WidgetZephyrwest Category Posts Widget | 12/8/2024 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as… | |
| Analizada | Media (5.4) | 0.33% | — | Zephyr-one Zephyr Project Manager | 3/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Alta (7.5) | 0.45% | — | Zephyr-one Zephyr Project Manager | 1/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99. | |
| Analizada | Media (5.4) | 0.77% | 💥 PoC | Dylanjkotze Zephyr Project Manager | 30/7/2024 | 17/6/2026 | The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Alta (8.8) | 0.44% | — | Zephyr-one Zephyr Project Manager | 9/7/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97. | |
| Analizada | Media (6.5) | 0.45% | — | Zephyrproject Zephyr | 3/7/2024 | 17/6/2026 | A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device | |
| Analizada | Media (6.5) | 0.47% | — | Zephyrproject Zephyr | 29/3/2024 | 17/6/2026 | An malicious BLE device can crash BLE victim device by sending malformed gatt packet | |
| Modificada | Alta (7.5) | 0.49% | — | Zephyrproject Zephyr | 15/3/2024 | 17/6/2026 | Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address. | |
| Analizada | Crítica (9.8) | 0.44% | — | Zephyrproject Zephyr | 29/2/2024 | 17/6/2026 | Possible buffer overflow in is_mount_point | |
| Analizada | Crítica (9.1) | 0.35% | — | Zephyrproject Zephyr | 19/2/2024 | 17/6/2026 | The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined… | |
| Analizada | Crítica (9.8) | 0.44% | — | Zephyrproject Zephyr | 18/2/2024 | 17/6/2026 | Signed to unsigned conversion esp32_ipm_send | |
| Analizada | Crítica (9.8) | 0.44% | — | Zephyrproject Zephyr | 18/2/2024 | 17/6/2026 | can: out of bounds in remove_rx_filter function | |
| Analizada | Crítica (9.8) | 0.44% | — | Zephyrproject Zephyr | 18/2/2024 | 17/6/2026 | Unchecked length coming from user input in settings shell | |
| Modificada | Media (6.1) | 0.36% | — | Zephyr Project Manager Project Zephyr Project Manager | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9. | |
| Modificada | Crítica (9.8) | 0.75% | — | Zephyrproject Zephyr | 21/11/2023 | 17/6/2026 | Possible variant of CVE-2021-3434 in function le_ecred_reconf_req. | |
| Modificada | Alta (8.8) | 0.39% | — | Zephyrproject Zephyr | 21/11/2023 | 17/6/2026 | An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, leading to DoS or potential RCE on the victim BLE device. | |
| Modificada | Alta (7.8) | 0.43% | — | Zephyrproject Zephyr | 26/10/2023 | 17/6/2026 | Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver | |
| Modificada | Alta (8.8) | 0.88% | — | Zephyrproject Zephyr | 25/10/2023 | 17/6/2026 | Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c | |
| Modificada | Crítica (9.8) | 0.88% | — | Zephyrproject Zephyr | 13/10/2023 | 17/6/2026 | Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows. | |
| Modificada | Alta (8.8) | 0.49% | — | Zephyrproject Zephyr | 13/10/2023 | 17/6/2026 | Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver | |
| Modificada | Alta (7.5) | 0.45% | — | Zephyrproject Zephyr | 13/10/2023 | 17/6/2026 | The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception. |