Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.4% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.36% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 1.2% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 1.0% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 1.3% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 0.47% | — | Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware | 8/7/2024 | 17/6/2026 | A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Media (6.6) | 0.43% | — | Mediatek Software Development KITOpenwrt | 3/6/2024 | 17/6/2026 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411. | |
| Analizada | Media (6.6) | 0.43% | — | Mediatek Software Development KITOpenwrt | 3/6/2024 | 17/6/2026 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332. | |
| Analizada | Media (4.4) | 0.17% | — | Mediatek Software Development KITOpenwrt | 3/6/2024 | 17/6/2026 | In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331. | |
| Analizada | Media (6.5) | 0.41% | — | Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.85% | — | IBM Java Software Development KIT | 14/5/2024 | 17/6/2026 | The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578. | |
| Analizada | Alta (7.5) | 1.4% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server | 3/5/2024 | 17/6/2026 | Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.5) | 1.8% | — | Microsoft Azure Software Development KIT | 12/3/2024 | 17/6/2026 | Azure SDK Spoofing Vulnerability | |
| Analizada | Crítica (9.8) | 0.98% | — | Mediatek Software Development KIT | 4/3/2024 | 17/6/2026 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019. | |
| Analizada | Crítica (9.8) | 47% | 💥 PoC | Mediatek Software Development KITOpenwrt | 4/3/2024 | 17/6/2026 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132. | |
| Analizada | Alta (7.5) | 0.40% | — | Silabs Gecko Software Development KIT | 21/2/2024 | 17/6/2026 | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. | |
| Modificada | Crítica (9.8) | 1.7% | — | Silabs Gecko Software Development KITWeston-embedded Uc-http | 20/2/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.46% | — | Oppo Usercenter Credit Software Development KIT | 20/2/2024 | 17/6/2026 | In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction. | |
| Analizada | Media (6.5) | 0.36% | — | Silabs Gecko Software Development KIT | 15/2/2024 | 17/6/2026 | A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Software Development KIT FOR Opencl | 14/2/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.53% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access. |