Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.19%—Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+537/9/20269/9/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue…
AnalizadaMedia (5.5)0.09%—Mediatek Mt2716 FirmwareMediatek Mt6835 FirmwareMediatek Mt6858 FirmwareMediatek Mt6878 Firmware+187/9/20269/9/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
AnalizadaMedia (6.5)0.29%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+474/5/202617/6/2026
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;…
AnalizadaMedia (6.5)0.22%—Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+644/5/202617/6/2026
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue…
AnalizadaAlta (8.8)0.34%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 FirmwareMediatek Mt6833 Firmware+587/4/202617/6/2026
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:…
AnalizadaAlta (8)0.29%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6779 FirmwareMediatek Mt6781 Firmware+547/4/202624/7/2026
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:…
AnalizadaMedia (6.5)0.31%—Mediatek Mt6813 FirmwareMediatek Mt6815 FirmwareMediatek Mt6835 FirmwareMediatek Mt6878 Firmware+157/4/202624/7/2026
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID:…
ModificadaMedia (6.5)0.36%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+817/4/202517/6/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028;…
ModificadaCrítica (9.8)1.00%—Draytek Vigor2620 FirmwareDraytek Vigorlte200 FirmwareDraytek Vigor2860 FirmwareDraytek Vigor2925 Firmware+1927/2/20255/7/2026
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and…
ModificadaCrítica (9.8)1.1%—Draytek Vigor3912 FirmwareDraytek Vigor2620 FirmwareDraytek Vigorlte200 FirmwareDraytek Vigor2860 Firmware+1927/2/20255/7/2026
Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earlier; Vigor2962 4.3.2.8 and earlier; Vigor3912 4.3.6.1 and…
AnalizadaAlta (8)0.33%—Draytek Vigor2620 FirmwareDraytek Vigor2915 FirmwareDraytek Vigor2866 FirmwareDraytek Vigor2766 Firmware+203/10/202417/6/2026
Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.
ModificadaAlta (7.5)0.27%—Draytek Vigor2620 FirmwareDraytek Vigor2915 FirmwareDraytek Vigor2866 FirmwareDraytek Vigor2766 Firmware+203/10/202417/6/2026
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
ModificadaCrítica (9.8)0.89%—Draytek Vigor3912 FirmwareDraytek Vigor2962 FirmwareDraytek Vigor3910 FirmwareDraytek Vigor165 Firmware+203/10/202417/6/2026
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.
AnalizadaAlta (8)1.4%—Draytek Vigor2952 FirmwareDraytek Vigor2620 FirmwareDraytek Vigor2915 FirmwareDraytek Vigor2866 Firmware+203/10/202417/6/2026
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
ModificadaMedia (6.1)0.27%—Draytek Vigor2620 FirmwareDraytek Vigor2915 FirmwareDraytek Vigor2866 FirmwareDraytek Vigor2766 Firmware+203/10/202417/6/2026
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
AnalizadaAlta (8)0.33%—Draytek Vigor2765 FirmwareDraytek Vigor2763 FirmwareDraytek Vigor2135 FirmwareDraytek Vigor166 Firmware+203/10/202417/6/2026
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.
AnalizadaAlta (8)0.33%—Draytek Vigor2620 FirmwareDraytek Vigor2915 FirmwareDraytek Vigor2866 FirmwareDraytek Vigor2766 Firmware+203/10/202417/6/2026
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.
ModificadaMedia (5.4)0.25%—Draytek Vigor3910 FirmwareDraytek Vigor3912 FirmwareDraytek Vigor2962 FirmwareDraytek Vigor165 Firmware+203/10/202417/6/2026
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
ModificadaCrítica (10)0.30%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+6113/8/202417/6/2026
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
AnalizadaMedia (6)0.19%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+6113/8/202417/6/2026
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.
ModificadaMedia (6.4)0.12%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+10113/8/202417/6/2026
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
ModificadaAlta (8.2)0.16%—AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+6513/8/202417/6/2026
An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
AnalizadaAlta (7.9)0.45%—AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
AnalizadaAlta (7.9)0.49%—AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
AnalizadaMedia (6)0.44%—AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.