Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | — | — | Nasa-ammos Ait-coreAI | 3/10/2026 | 3/10/2026 | CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry… | |
| Aplazada | Crítica (9.1) | 0.86% | — | Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI | 21/7/2026 | 23/7/2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In… | |
| Analizada | Alta (7.3) | 0.55% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution. | |
| Analizada | Alta (7.5) | 0.47% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file. | |
| Analizada | Alta (7.5) | 0.45% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands. | |
| Analizada | Alta (7.5) | 0.44% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string. | |
| Analizada | Alta (7.5) | 0.44% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet. | |
| Analizada | Crítica (9.8) | 0.61% | — | Nasa AIT Core | 21/5/2024 | 17/6/2026 | NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions. |