Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.30% | — | Suzuki SwiftAIAlpsalpine Cwtr53r0AI | 25/6/2026 | 26/6/2026 | Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Analizada | Alta (8) | 0.69% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming… | |
| Analizada | Alta (7.4) | 0.28% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious… | |
| Analizada | Alta (8) | 0.13% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TIDAL music streaming… | |
| Analizada | Alta (7.4) | 0.29% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a… | |
| Analizada | Media (6.8) | 0.25% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.6) | 0.73% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (7.4) | 0.29% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to… | |
| Analizada | Alta (8) | 0.46% | — | Alpsalpine Ilx-f509 Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (5.3) | 0.68% | — | Alpsalpine Ilx-f509 Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of… | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (4.6) | 0.26% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 0.50% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target… | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 0.79% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (5.4) | 0.66% | — | Alpine Project Alpine | 28/12/2022 | 17/6/2026 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold… | |
| Modificada | Alta (7.5) | 0.84% | — | Alpine Project Alpine | 28/12/2022 | 17/6/2026 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds. | |
| Modificada | Media (5.9) | 0.91% | — | Alpine Project Alpine | 3/11/2022 | 17/6/2026 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. | |
| Modificada | Media (5.4) | 0.63% | — | Thealpinepress Alpine Phototile FOR Pinterest | 23/8/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress. | |
| Modificada | Media (6.1) | 0.73% | — | Thealpinepress Alpine-photo-tile-for-instagram | 23/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. | |
| Modificada | Alta (7.8) | 0.40% | — | Alpsalpine Touchpad Driver | 31/1/2022 | 17/6/2026 | Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection. | |
| Modificada | Media (5.9) | 1.6% | — | Alpine Project Alpine | 10/8/2021 | 17/6/2026 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. |