Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.43% | — | Wtv676 Hb6035 WEB InterfaceAIWtv776 Hb6035 WEB InterfaceAI | 16/9/2026 | 18/9/2026 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode,… | |
| Aplazada | Media (5.3) | 0.29% | — | Ebyte WEB Management InterfaceAI | 28/8/2026 | 31/8/2026 | The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions. | |
| Aplazada | Crítica (9.3) | 0.80% | — | Ebyte Device WEB Management InterfaceAI | 28/8/2026 | 31/8/2026 | Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Intel ALH Digital Audio Interface DriverAIZephyrproject ZephyrAI | 12/8/2026 | 26/8/2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const uint8_t alh_handshake_map[64] array and scales a FIFO register address, so an out-of-range stream_id… | |
| Pendiente de análisis | Media (6.3) | 1.1% | — | GMS Command-line InterfaceAI | 11/8/2026 | 28/8/2026 | An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (5.6) | 0.14% | — | Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System… | |
| Aplazada | Alta (8.4) | 0.17% | — | Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '… | |
| Aplazada | Alta (8.2) | 0.16% | — | Asus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a… | |
| Aplazada | Alta (8.7) | 0.71% | — | Aclara Metrum Cellular WEB InterfaceAI | 24/6/2026 | 25/6/2026 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without restriction. Such… | |
| Modificada | Media (6.9) | 0.14% | — | Erlang ERL InterfaceErlang/otp | 10/6/2026 | 24/9/2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to… | |
| Analizada | Alta (8.6) | 0.58% | — | Openairinterface5g | 1/6/2026 | 22/7/2026 | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kpm_subs.c (lines 182 and 197) compute PRB usage percentages by dividing by the… | |
| Pendiente de análisis | Alta (7.3) | 0.12% | — | Asus System Control InterfaceAI | 29/5/2026 | 21/7/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on… | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | Asus System Control InterfaceAI | 8/5/2026 | 17/9/2026 | An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information. | |
| Analizada | Media (6.6) | 0.24% | — | Oracle Cloud Native Environment Command Line Interface | 6/5/2026 | 17/6/2026 | Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a… | |
| Analizada | Media (5.6) | 0.14% | — | Home-assistant-ecosystem Home Assistant Command-line Interface | 21/4/2026 | 17/6/2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This… | |
| Analizada | Alta (7.5) | 0.35% | — | Openairinterface Oai-cn5g-amf | 8/4/2026 | 25/7/2026 | OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade security context can lead to the… | |
| Analizada | Alta (7.5) | 0.66% | — | Openairinterface Oai-cn5g-amf | 8/4/2026 | 25/7/2026 | OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. AUSF crashes on receiving this… | |
| Analizada | Crítica (9.8) | 0.66% | — | Openairinterface Oai-cn5g-amf | 7/4/2026 | 17/6/2026 | In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept!… | |
| Analizada | Media (4.8) | 0.29% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, the formatInfo() function in queries.js renders data.upstream, data.client.ip, and data.ede.text into HTML without escaping when a user expands a query row in the Query… | |
| Analizada | Media (6.1) | 0.37% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed directly into HTML value="" attributes without escaping in settings-advanced.js, enabling HTML attribute… | |
| Analizada | Media (6.1) | 0.25% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, client hostnames and IP addresses from the FTL database are rendered into the DOM without escaping in network.js (Network page) and charts.js/index.js (Dashboard chart… | |
| Analizada | Media (6.1) | 0.32% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, a reflected DOM-based XSS vulnerability in taillog.js allows an unauthenticated attacker to inject arbitrary HTML into the Pi-hole admin interface by crafting a… | |
| Analizada | Alta (7.5) | 0.49% | — | Openairinterface Oai-cn5g-amf | 6/4/2026 | 17/6/2026 | OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome. |