Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Media (6.8) | 0.21% | — | Bosch Infotainment ECUAINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server. First identified on… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Crítica (9.3) | 0.17% | — | Bosch Infotainment ECUAIBosch Rh850AINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the… | |
| Aplazada | Media (6.5) | 0.29% | — | Bosch Infotainment ECUAINissan Leaf ZE1AIRedbendAI | 22/1/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not… | |
| Aplazada | Media (5.4) | 0.34% | — | Skoda Mib3 InfotainmentAI | 28/6/2025 | 17/6/2026 | A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vulnerability was originally discovered in Skoda Superb III car… | |
| Aplazada | Alta (8) | 0.42% | — | Skoda Mib3 Infotainment UnitAI | 28/6/2025 | 17/6/2026 | A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in… | |
| Aplazada | Baja (3.3) | 0.23% | — | Skoda Mib3 Infotainment UnitAI | 28/6/2025 | 17/6/2026 | An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The… | |
| Aplazada | Alta (7.3) | 0.88% | — | Oncord Plus Android Infotainment SystemAI | 15/4/2025 | 17/6/2026 | An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component. | |
| Analizada | Media (6.8) | 0.88% | — | Visteon Infotainment | 22/11/2024 | 17/6/2026 | Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (6.8) | 0.88% | — | Visteon Infotainment | 22/11/2024 | 17/6/2026 | Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (6.8) | 0.88% | — | Visteon Infotainment | 22/11/2024 | 17/6/2026 | Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.32% | — | Visteon Infotainment | 22/11/2024 | 17/6/2026 | Visteon Infotainment App SoC Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. Although authentication is required to exploit this vulnerability, the existing… | |
| Analizada | Alta (7.8) | 0.17% | — | Visteon Infotainment | 22/11/2024 | 17/6/2026 | Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. An attacker must first obtain the ability to execute low-privileged code… | |
| Analizada | Media (6.8) | 0.56% | — | Visteon Infotainment Firmware | 22/11/2024 | 17/6/2026 | Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Modificada | Media (4.6) | 0.35% | — | GM Mylink Infotainment System | 8/9/2023 | 17/6/2026 | Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (build version) vehicle causes a Denial of Service (DoS) in the in-car infotainment system. | |
| Modificada | Media (6.8) | 1.8% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object. | |
| Modificada | Media (4.3) | 0.50% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets. | |
| Modificada | Media (6.8) | 0.50% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name. | |
| Modificada | Media (6.8) | 0.51% | — | VW Discover Media Infotainment System | 16/6/2023 | 17/6/2026 | A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers to cause a Denial of Service (DoS) via supplying crafted media files when connecting a device to the vehicle's USB plug and play feature. | |
| Modificada | Media (6.8) | 0.36% | — | GM Mylink Infotainment System | 27/3/2023 | 17/6/2026 | The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to cause a denial of service (temporary failure of Media Player functionality) via a crafted MP3 file. |