Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.11%—Matter Project ChipAIMatter Standard SpecificationAI21/9/202624/9/2026
An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component
AplazadaMedia (6.1)0.38%—PochippAI19/9/202621/9/2026
The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due to insufficient output escaping , which reads $_GET['keyword'], applies only sanitize_text_field() (which strips tags but leaves double quotes intact) and…
Pendiente de análisisMedia (5.6)0.20%—Microchip An1044AIMicrochip An953AIMicrochip Sw300052AI12/9/202616/9/2026
Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.
AplazadaAlta (7.3)0.14%—Microchip Sama5d4AI24/8/202631/8/2026
Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.
AplazadaAlta (7.6)0.23%—Rockchip Rk3588sAI19/8/20261/10/2026
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD). The code reads the header of the next-stage loader twice. The header contains hashes of the executable modules and is signed with a private key, the public part of…
AplazadaAlta (7)0.17%—Felica IC ChipAI21/7/202621/7/2026
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
AnalizadaMedia (5.3)0.21%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
AnalizadaMedia (5.3)0.23%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
AnalizadaMedia (4.6)0.39%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
AnalizadaMedia (5.1)0.23%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Pendiente de análisisAlta (8.5)0.10%—AMD Chipset DriverAI15/5/202617/6/2026
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
AnalizadaAlta (8.7)0.23%—Microchip Istax16/4/202612/8/2026
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
AnalizadaMedia (5.5)0.32%—Microchip Timeprovider 4100 Firmware28/3/202612/8/2026
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.
AplazadaMedia (5.4)0.23%—PochippAI13/3/202617/6/2026
Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through < 1.18.9.
AnalizadaCrítica (9.3)0.26%—Microchip Timepictra28/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.
AnalizadaCrítica (9.3)0.44%—Microchip Timepictra28/2/202617/6/2026
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.
ModificadaMedia (5.7)0.10%—Microchip Timeprovider 4100 Firmware24/2/202617/6/2026
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.
AplazadaMedia (5.4)0.09%—Intel Chipset SoftwareAI10/2/202617/6/2026
Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result…
AplazadaAlta (7)0.23%—Asus MotherboardsAIIntel B460 ChipsetAIIntel B560 ChipsetAIIntel B660 ChipsetAI+1017/12/202530/9/2026
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software…
AplazadaMedia (5.3)0.25%—PochippAI16/12/202517/6/2026
Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through <= 1.18.0.
AnalizadaMedia (6.5)0.31%—Chipsalliance Rocketchip10/11/202517/6/2026
A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP…
ModificadaAlta (7.1)0.38%—Microchip Timeprovider 4100 Firmware20/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5.
ModificadaAlta (8.9)1.4%—Microchip Timeprovider 4100 Firmware20/10/202517/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
ModificadaAlta (8.9)1.4%—Microchip Timeprovider 4100 Firmware20/10/202517/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
AnalizadaAlta (7.5)0.64%—Chipsalliance Rocket-chip30/9/202517/6/2026
An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between exception handling and MRET return mechanisms in the CSR logic when an exception is…