Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.69%—Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI9/9/202610/9/2026
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
Pendiente de análisisMedia (6.8)0.08%—Nordic Semiconductor Nrf5340AINordic Semiconductor NRF Connect SDKAI7/9/20269/9/2026
—
AplazadaCrítica (9.3)15%—Netflix ConductorAI30/6/202614/7/2026
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication.…
Pendiente de análisisAlta (7.5)0.28%—Nordic Semiconductor Ironside SEAI15/4/202617/6/2026
Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
AplazadaCrítica (9.3)1.6%—Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI27/1/202617/6/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue…
AplazadaAlta (8.5)0.13%—Fujitsu Security Solution Authconductor Client BasicAI7/1/202617/6/2026
Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If this vulnerability is exploited, an attacker who can log in to the Windows system where the affected product is installed may execute arbitrary code with SYSTEM privilege and/or modify the registry…
AplazadaAlta (8.6)0.23%—Nordic Semiconductor Nrf52810AI5/9/202517/6/2026
On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of modification to the hardware system possible.
AplazadaAlta (8.4)0.43%—Lattice Semiconductor Ispvm SystemAI13/8/202516/6/2026
Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, allowing a specially crafted file to overwrite memory on the stack. This can…
AplazadaCrítica (9.8)0.71%—Netflix ConductorAI30/6/202517/6/2026
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.
AplazadaCrítica (10)1.1%—Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance RouterAI27/6/202417/6/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors that are running in high-availability…
AplazadaAlta (7.8)0.22%—Realtek Semiconductor Corp Realtek High Definition Audio Function DriverAI22/5/202417/6/2026
An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
AplazadaAlta (8.4)0.18%—Realtek Semiconductor Corp Realtek IO DriverAI22/5/202417/6/2026
An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
AplazadaAlta (7.3)0.36%—Nordic Semiconductor NRF Sniffer FOR Bluetooth LEAI14/5/202417/6/2026
extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.
ModificadaCrítica (9.8)1.7%—Netflix Conductor16/6/202017/6/2026
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to…
ModificadaMedia (6.5)0.76%—Dialog-semiconductor Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to link layer packets with a payload length larger than expected, allowing attackers in radio range to cause a buffer overflow via a crafted packet. This affects, for example, August Smart Lock.
ModificadaMedia (5.7)0.63%—Dialog-semiconductor Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
ModificadaAlta (8.1)1.7%—Verifone Verix Multi-app Conductor26/3/201917/6/2026
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.
ModificadaMedia (5)2.1%—Cisco Telepresence Video Communication ServerCisco Telepresence Conductor7/2/201917/6/2026
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred…
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaMedia (4.3)1.6%—Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server19/10/201717/6/2026
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial…
ModificadaMedia (4.3)1.8%—Cisco Videoscape ConductorCisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.
ModificadaAlta (10)4.3%—Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software13/3/201517/6/2026
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs…
ModificadaAlta (7.8)1.9%—Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software13/3/201517/6/2026
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka…
ModificadaMedia (5.5)1.2%—Redhat Aeolus Conductor12/3/201316/6/2026
The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.
ModificadaAlta (7.5)1.1%—Cstech Webconductor31/1/201316/6/2026
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter.