Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 27/8/2026 | 28/8/2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to… | |
| Aplazada | Media (6) | 0.24% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and… | |
| Aplazada | Alta (8.5) | 0.23% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect… | |
| Aplazada | Alta (8.7) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos.… | |
| Aplazada | Crítica (9.4) | 0.09% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 21/8/2026 | 26/8/2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE,… | |
| Aplazada | Alta (8.4) | 0.17% | — | IRU INC Kandji AgentAI | 15/6/2026 | 17/6/2026 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality. | |
| Analizada | Alta (7.5) | 0.60% | — | DJI Mavic Mini FirmwareDJI Spark FirmwareDJI Mini SE Firmware | 4/3/2026 | 17/6/2026 | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem | |
| Aplazada | Baja (1.3) | 0.41% | — | DJI Mavic MiniAIDJI Mavic AIRAIDJI SparkAIDJI Mavic Mini SEAI | 2/2/2026 | 17/6/2026 | A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within the local network.… | |
| Aplazada | Baja (1.3) | 0.24% | — | DJI Mavic SparkAIDJI Mavic AIRAIDJI Mavic MiniAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attacker needs to be present on the local network. A high complexity level is… | |
| Aplazada | Media (6.6) | 0.29% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic Mini 3 PROAI | 2/4/2024 | 17/6/2026 | An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself. | |
| Aplazada | Media (5.2) | 0.24% | — | DJI Mavic Mini 3 PROAI | 2/4/2024 | 17/6/2026 | A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication. | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the sdk_printf function implemented in the libv2_sdk.so… | |
| Aplazada | Media (6.8) | 0.24% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in… | |
| Aplazada | Media (6.8) | 0.24% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_receive_session_packet_ack function implemented in the libv2_sdk.so library used by… | |
| Aplazada | Media (6.8) | 0.25% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a crafted payload triggering an unsafe memory write operation in the my_tcp_receive function implemented in the libv2_sdk.so… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the process_push_file function implemented in the libv2_sdk.so library used… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the pull_file_v2_proc function implemented in the libv2_sdk.so library used… | |
| Modificada | Media (5.5) | 0.30% | — | MWM Edjing MIX | 30/5/2023 | 17/6/2026 | An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files. | |
| Modificada | Crítica (9.8) | 0.94% | — | MWM Edjing MIX | 30/5/2023 | 17/6/2026 | An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database. | |
| Modificada | Media (5.9) | 0.91% | — | DJI Spark Firmware | 27/3/2023 | 17/6/2026 | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the attacker would need to send many DHCP request… | |
| Modificada | Alta (7.5) | 0.71% | — | DJI Mavic 3 FirmwareDJI RC PRO FirmwareDJI AIR 2S FirmwareDJI AIR 2 Firmware+7 | 29/4/2022 | 17/6/2026 | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol. | |
| Modificada | Alta (7.8) | 1.5% | — | DJI Mavic 2 Firmware | 18/2/2021 | 17/6/2026 | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet. | |
| Modificada | Media (5.4) | 0.27% | — | Djinnworks Stickman SKI Racer | 9/9/2014 | 17/6/2026 | The Stickman Ski Racer (aka com.djinnworks.StickmanSkiRacer.free) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Djinnworks Line Runner (free) | 9/9/2014 | 17/6/2026 | The Line Runner (Free) (aka com.djinnworks.linerunnerfree) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |