Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7)——Android BluetoothAI5/10/20266/10/2026
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
RecibidaAlta (8.8)——Android BluetoothAI5/10/20266/10/2026
In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Pendiente de análisisAlta (8.9)0.39%—Bluetooth Mesh SDKAI28/8/20268/9/2026
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Pendiente de análisisMedia (5.9)0.25%—Realtek BEE Bluetooth HCI DriverAI11/8/202626/8/2026
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and…
Pendiente de análisisAlta (8.8)0.32%—Bluetooth LEAI26/5/202623/7/2026
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
Pendiente de análisisAlta (8.4)0.21%—Dynabook Bluetooth Acpi DriversAI13/4/202617/6/2026
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AnalizadaMedia (6.8)0.32%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. The Secure Boot process forms a chain of trust by verifying all mutable software entities involved in the Application…
AnalizadaMedia (4.6)0.13%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previous Wi-Fi networks.…
AnalizadaMedia (6.8)0.21%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be executed upon running.…
AnalizadaAlta (7.5)0.37%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with…
ModificadaMedia (6.5)0.28%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202525/9/2026
An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the current device from its user and would…
AnalizadaAlta (8.8)0.56%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202525/9/2026
An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the attacker's code. As the device does not perform checks on upgrades, this results in…
AnalizadaCrítica (9.8)0.43%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202528/9/2026
The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker…
AplazadaAlta (8.8)11%—Airoha Bluetooth Audio SDKAI4/8/202517/6/2026
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AplazadaAlta (8.8)8.7%—Airoha Bluetooth Audio SDKAI4/8/20258/9/2026
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AplazadaAlta (8.8)9.2%—Airoha Bluetooth Audio SDKAI4/8/202517/6/2026
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AplazadaAlta (8.5)0.19%—Realtek Bluetooth HCI AdaptorAI2/6/202517/6/2026
Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to…
AplazadaMedia (6.8)0.30%—Intel Wireless BluetoothAI13/11/202417/6/2026
Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (6.6)0.14%—Samsung BluetoothadapterAI6/11/202417/6/2026
Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.
AplazadaMedia (6.5)0.26%—Cypress Bluetooth SDKAI1/11/202417/6/2026
An issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via supplying a crafted LL_PAUSE_ENC_REQ packet.
AplazadaMedia (6.8)0.24%—Bluetooth Core SpecificationsAI1/10/202417/6/2026
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X…
AnalizadaBaja (3.1)0.19%—Silabs Bluetooth LOW Energy Software Development KIT12/7/202417/6/2026
Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.