Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1271 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.39%💥 PoCOpswat Appremover DriverAI16/7/202617/7/2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
AplazadaCrítica (9)0.64%—DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI15/7/202616/7/2026
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so…
AplazadaBaja (2)0.12%—Suse Virtual Machine Driver PackAI14/7/202629/9/2026
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this currently. This issue affects Virtual Machine…
AplazadaCrítica (9.4)0.16%—XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,…
AplazadaCrítica (9.4)0.16%—Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,…
AplazadaCrítica (9.4)0.16%—XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are:
AnalizadaMedia (6.1)0.56%💥 ExploitAppium/base-driver8/7/202615/7/2026
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError…
Pendiente de análisisAlta (8.4)0.14%—Fluxink Color Management DriverAILenovo Tcnperipheral64AI7/7/202621/7/2026
FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK…
AnalizadaAlta (8.2)0.24%—Postgresql Jdbc Driver6/7/20269/7/2026
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who…
AplazadaMedia (6.8)0.17%💥 PoCToshiba Generic IO Memory Access DriverAIDynabook Generic IO Memory Access DriverAI25/6/202625/6/2026
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.
Pendiente de análisisAlta (8.5)0.17%—Realtek High Definition Audio DriverAI19/6/202629/9/2026
Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service path. Attackers can insert an executable file in the unquoted path and restart the service to execute code with LocalSystem…
AplazadaAlta (8.5)0.18%—Ricoh Printer DriversAIKonicaminolta Printer DriversAI15/6/202624/7/2026
Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver.
AnalizadaMedia (5.9)0.10%—Samsung Android USB Driver5/6/202630/6/2026
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.
Pendiente de análisisMedia (5.1)0.16%—Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI29/5/202621/7/2026
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800…
AnalizadaMedia (4.7)0.09%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to denial of service.
Pendiente de análisisMedia (5.6)0.15%—Nvidia GPU Display Driver FOR LinuxAI26/5/202624/7/2026
NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of service, data tampering,…
AnalizadaMedia (6.5)0.16%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead…
AnalizadaAlta (7.1)0.17%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
AnalizadaMedia (5.5)0.16%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.8)0.15%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaAlta (7.8)0.20%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaAlta (7.8)0.21%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code…
AnalizadaAlta (7.8)0.14%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaAlta (7.8)0.22%—Nvidia GPU Display Driver26/5/202624/7/2026
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
AnalizadaAlta (8.8)0.19%—Nvidia GPU Display Driver26/5/202620/7/2026
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.