Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.50% | — | Nasa Core Flight SystemAI | 4/8/2026 | 31/8/2026 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 30/7/2026 | 31/8/2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a… | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 16/7/2026 | 17/7/2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. | |
| Analizada | Baja (2.1) | 0.32% | — | Nasa Core Flight System | 3/4/2026 | 24/7/2026 | A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The exploitability is told to be difficult. A… | |
| Analizada | Media (5.1) | 0.33% | — | Nasa Core Flight System | 3/4/2026 | 24/7/2026 | A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early through an issue report but has not responded… | |
| Analizada | Media (5.3) | 0.61% | — | Nasa Core Flight System | 3/4/2026 | 24/7/2026 | A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to… | |
| Analizada | Baja (1.1) | 0.36% | — | Nasa Core Flight System | 3/4/2026 | 24/7/2026 | A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The… | |
| Analizada | Alta (7.5) | 0.48% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service. | |
| Analizada | Crítica (9.8) | 0.51% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform. | |
| Analizada | Alta (7.5) | 0.48% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module. | |
| Analizada | Alta (7.5) | 0.60% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system. |