Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.38% | — | Berkeley BoomAIBerkeley BoomtileAI | 19/8/2026 | 9/9/2026 | An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark… | |
| Aplazada | Alta (7.8) | 0.15% | — | Berkeley BoomAI | 18/8/2026 | 9/9/2026 | Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the… | |
| Analizada | Alta (7.5) | 0.41% | — | Berkeley-abc ABC | 25/6/2025 | 17/6/2026 | berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes. | |
| Modificada | Media (5.5) | 0.24% | — | Huawei Bla-a09 FirmwareHuawei Bla-tl00b FirmwareHuawei Berkeley-l09 FirmwareHuawei Duke-l09 Firmware+9 | 11/9/2020 | 17/6/2026 | Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions earlier than 8.0.0.163(C10),versions earlier than 8.0.0.163(C432),Versions earlier than 8.0.0.163(C636),Versions earlier… | |
| Modificada | Alta (7) | 0.43% | — | Oracle Berkeley DB | 15/7/2020 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 18.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Media (4.6) | 0.21% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Anne-al00 Firmware+24 | 8/6/2020 | 17/6/2026 | Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in… | |
| Modificada | Media (6.5) | 0.34% | — | Huawei Anne-al00 FirmwareHuawei Berkeley-l09 FirmwareHuawei Cd16-10 FirmwareHuawei Cd17-10 Firmware+14 | 21/5/2020 | 17/6/2026 | There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly. Affected product versions include: Anne-AL00 Versions earlier than 9.1.0.331(C675E9R1P3T8); Berkeley-L09… | |
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2… | |
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1… | |
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa | Google AndroidHuawei Berkeley-l09 FirmwareHuawei Columbia-al10b FirmwareHuawei Columbia-l29d Firmware+25 | 10/3/2020 | 17/6/2026 | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa | Google AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+73 | 11/10/2019 | 17/6/2026 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing… | |
| Modificada | Alta (8.1) | 2.7% | — | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Alta (7) | 0.45% | — | Oracle Berkeley DB | 23/7/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 12.1.6.1.26, 12.1.6.1.29, 12.1.6.1.36, 12.1.6.2.23 and 12.1.6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to… | |
| Modificada | Alta (7) | 0.45% | — | Oracle Berkeley DB | 23/7/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 12.1.6.1.26, 12.1.6.1.29, 12.1.6.1.36, 12.1.6.2.23 and 12.1.6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to… | |
| Modificada | Alta (7) | 0.45% | — | Oracle Berkeley DB | 23/7/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 12.1.6.1.26, 12.1.6.1.29, 12.1.6.1.36, 12.1.6.2.23 and 12.1.6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to… | |
| Modificada | Alta (7) | 0.45% | — | Oracle Berkeley DB | 23/7/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 12.1.6.1.26, 12.1.6.1.29, 12.1.6.1.36, 12.1.6.2.23 and 12.1.6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to… | |
| Modificada | Alta (7) | 0.45% | — | Oracle Berkeley DB | 23/7/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 12.1.6.1.26, 12.1.6.1.29, 12.1.6.1.36, 12.1.6.2.23 and 12.1.6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to… | |
| Modificada | Baja (3.3) | 0.60% | — | Oracle Berkeley DB | 23/4/2019 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138, prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to… | |
| Modificada | Media (5.5) | 0.55% | — | Huawei Berkeley-al20 FirmwareHuawei Berkeley-bd Firmware | 19/4/2018 | 17/6/2026 | The Mali Driver of Huawei Berkeley-AL20 and Berkeley-BD smart phones with software Berkeley-AL20 8.0.0.105(C00), 8.0.0.111(C00), 8.0.0.112D(C00), 8.0.0.116(C00), 8.0.0.119(C00), 8.0.0.119D(C00), 8.0.0.122(C00), 8.0.0.132(C00), 8.0.0.132D(C00), 8.0.0.142(C00), 8.0.0.151(C00), Berkeley-BD 1.0.0.21, 1.0.0.22, 1.0.0.23,… | |
| Modificada | Alta (7) | 0.44% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Alta (7) | 0.42% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Alta (7) | 0.42% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Alta (7) | 0.42% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Alta (7) | 0.42% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… | |
| Modificada | Alta (7) | 0.42% | — | Oracle Berkeley DB | 24/4/2017 | 17/6/2026 | Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human… |