Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.11% | — | Matter Project ChipAIMatter Standard SpecificationAI | 21/9/2026 | 24/9/2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component | |
| Aplazada | Media (6.1) | 0.38% | — | PochippAI | 19/9/2026 | 21/9/2026 | The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due to insufficient output escaping , which reads $_GET['keyword'], applies only sanitize_text_field() (which strips tags but leaves double quotes intact) and… | |
| Pendiente de análisis | Media (5.6) | 0.20% | — | Microchip An1044AIMicrochip An953AIMicrochip Sw300052AI | 12/9/2026 | 16/9/2026 | Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6. | |
| Aplazada | Alta (7.3) | 0.14% | — | Microchip Sama5d4AI | 24/8/2026 | 31/8/2026 | Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4. | |
| Aplazada | Alta (7.6) | 0.23% | — | Rockchip Rk3588sAI | 19/8/2026 | 1/10/2026 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD). The code reads the header of the next-stage loader twice. The header contains hashes of the executable modules and is signed with a private key, the public part of… | |
| Aplazada | Alta (7) | 0.17% | — | Felica IC ChipAI | 21/7/2026 | 21/7/2026 | Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with. | |
| Analizada | Media (5.3) | 0.21% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.3) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0. | |
| Analizada | Media (4.6) | 0.39% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.1) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Chipset DriverAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Analizada | Alta (8.7) | 0.23% | — | Microchip Istax | 16/4/2026 | 12/8/2026 | A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03. | |
| Analizada | Media (5.5) | 0.32% | — | Microchip Timeprovider 4100 Firmware | 28/3/2026 | 12/8/2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0. | |
| Aplazada | Media (5.4) | 0.23% | — | PochippAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through < 1.18.9. | |
| Analizada | Crítica (9.3) | 0.26% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Analizada | Crítica (9.3) | 0.44% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Modificada | Media (5.7) | 0.10% | — | Microchip Timeprovider 4100 Firmware | 24/2/2026 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5. | |
| Aplazada | Media (5.4) | 0.09% | — | Intel Chipset SoftwareAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result… | |
| Aplazada | Alta (7) | 0.23% | — | Asus MotherboardsAIIntel B460 ChipsetAIIntel B560 ChipsetAIIntel B660 ChipsetAI+10 | 17/12/2025 | 30/9/2026 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software… | |
| Aplazada | Media (5.3) | 0.25% | — | PochippAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through <= 1.18.0. | |
| Analizada | Media (6.5) | 0.31% | — | Chipsalliance Rocketchip | 10/11/2025 | 17/6/2026 | A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP… | |
| Modificada | Alta (7.1) | 0.38% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5. | |
| Modificada | Alta (8.9) | 1.4% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. | |
| Modificada | Alta (8.9) | 1.4% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. | |
| Analizada | Alta (7.5) | 0.64% | — | Chipsalliance Rocket-chip | 30/9/2025 | 17/6/2026 | An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between exception handling and MRET return mechanisms in the CSR logic when an exception is… |