Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (8.8)0.36%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)1.2%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)1.0%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)1.3%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)0.47%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaMedia (6.6)0.43%—Mediatek Software Development KITOpenwrt3/6/202417/6/2026
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411.
AnalizadaMedia (6.6)0.43%—Mediatek Software Development KITOpenwrt3/6/202417/6/2026
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.
AnalizadaMedia (4.4)0.17%—Mediatek Software Development KITOpenwrt3/6/202417/6/2026
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331.
AnalizadaMedia (6.5)0.41%—Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/5/202417/6/2026
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.85%—IBM Java Software Development KIT14/5/202417/6/2026
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.
AnalizadaAlta (7.5)1.4%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AnalizadaAlta (7.5)1.8%—Microsoft Azure Software Development KIT12/3/202417/6/2026
Azure SDK Spoofing Vulnerability
AnalizadaCrítica (9.8)0.98%—Mediatek Software Development KIT4/3/202417/6/2026
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.
AnalizadaCrítica (9.8)47%💥 PoCMediatek Software Development KITOpenwrt4/3/202417/6/2026
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.
AnalizadaAlta (7.5)0.40%—Silabs Gecko Software Development KIT21/2/202417/6/2026
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Uc-http20/2/202417/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
AnalizadaAlta (7.5)0.46%—Oppo Usercenter Credit Software Development KIT20/2/202417/6/2026
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
AnalizadaMedia (6.5)0.36%—Silabs Gecko Software Development KIT15/2/202417/6/2026
A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.
ModificadaAlta (7.8)0.19%—Intel Software Development KIT FOR Opencl14/2/202417/6/2026
Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.53%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
ModificadaAlta (7.8)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaCrítica (9.8)1.7%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.