Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.2) | 0.24% | — | Semtech Loramac-nodeAI | 14/8/2026 | 26/8/2026 | The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured decoder. In frag_transport_package_callback() the value frag_counter = hdr->frag_index_n & 0x3FFF is taken… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Semtech Lr11xxAI | 7/4/2026 | 24/7/2026 | The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | Semtech Lr11xxAI | 7/4/2026 | 24/7/2026 | The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided encrypted firmware package block-by-block to… | |
| Pendiente de análisis | Media (5.4) | 0.24% | — | Semtech Lora Lr11xxxAI | 7/4/2026 | 24/7/2026 | An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can… | |
| Analizada | Media (6.9) | 0.18% | — | Emtec ZOC | 22/3/2026 | 17/6/2026 | ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a crafted payload into the Shell configuration field and trigger a crash when accessing the Command Shell… | |
| Aplazada | Media (5.1) | 0.33% | — | Demtec GraphyticsAI | 15/4/2025 | 17/6/2026 | A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (5.3) | 0.43% | — | Demtec GraphyticsAI | 15/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 1.6% | — | Semtech Loramac-node | 6/10/2022 | 17/6/2026 | LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can lead to an 65280-byte out-of-bounds write. The function `ProcessRadioRxDone` implicitly expects… | |
| Modificada | Crítica (9.8) | 1.1% | — | Emtec ZOC | 26/8/2021 | 17/6/2026 | EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198. | |
| Modificada | Crítica (9.8) | 1.2% | — | Emtec ZOC | 6/6/2021 | 17/6/2026 | EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title… | |
| Modificada | Alta (8.8) | 0.92% | — | Semtech Loramac-node | 23/6/2020 | 17/6/2026 | In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4. | |
| Modificada | Media (5) | 0.95% | — | Semtech Lora Basics Station | 22/6/2020 | 17/6/2026 | In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug is triggered on 32-bit machines when the CUPS server responds with a message (https://doc.sm.tc/station/cupsproto.html#http-post-response) where the signature length is larger than 2 GByte (never… | |
| Modificada | Alta (7.5) | 5.6% | — | Emtec Pyrobatchftp | 5/10/2017 | 17/6/2026 | EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash). |