Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.27% | — | Bosch Sensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}}… | |
| Pendiente de análisis | Alta (8) | 0.31% | — | Boschsensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | Bosch Bme690 SensorapiAI | 10/9/2026 | 10/9/2026 | An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping… | |
| Pendiente de análisis | Alta (8.4) | 0.19% | — | Bosch Sensortec Bhi385 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event… | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Bosch Sensortec Bhi360 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875).… | |
| Aplazada | Alta (8.7) | 0.35% | — | Bosch Smart HomeAI | 26/8/2026 | 8/9/2026 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions. | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Bosch Cpp13 IP CameraAIBosch Cpp14 IP CameraAI | 23/7/2026 | 1/10/2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Bosch Configuration ManagerAI | 23/7/2026 | 1/10/2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Bosch VMSAIBosch VMS Central ServerAI | 15/4/2026 | 17/6/2026 | Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk space via network interface. | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.38% | — | Bosch Rexroth IndraworksBosch Rexroth Ua.testclient | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user… | |
| Analizada | Alta (8.8) | 0.38% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires… | |
| Aplazada | Media (6.8) | 0.20% | — | Bosch Infotainment ECUAINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server. First identified on… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Crítica (9.3) | 0.17% | — | Bosch Infotainment ECUAIBosch Rh850AINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the… | |
| Aplazada | Alta (8.8) | 0.34% | — | Bosch Smart HomeAI | 12/2/2026 | 17/6/2026 | Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and gain unauthorized access to the… | |
| Aplazada | Media (6.5) | 0.29% | — | Bosch Infotainment ECUAINissan Leaf ZE1AIRedbendAI | 22/1/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not… | |
| Aplazada | Media (5.3) | 0.44% | — | Boschrexroth Ctrlx OSAI | 30/4/2025 | 17/6/2026 | A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests. | |
| Aplazada | Alta (7.5) | 0.49% | — | Boschrexroth IndradriveAI | 13/11/2024 | 17/6/2026 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages. | |
| Aplazada | Alta (8.4) | 0.20% | — | Bosch Smart HomeAI | 24/10/2024 | 5/7/2026 | Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |
| Aplazada | Alta (8.8) | 1.2% | — | Bosch Network SynchronizerAI | 25/3/2024 | 17/6/2026 | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device. | |
| Modificada | Crítica (9.8) | 0.76% | — | Bosch Nexo-os | 10/1/2024 | 17/6/2026 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |