Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.6) | 0.29% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the sdk_printf function implemented in the libv2_sdk.so… | |
| Aplazada | Media (6.8) | 0.24% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in… | |
| Aplazada | Media (6.8) | 0.24% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_receive_session_packet_ack function implemented in the libv2_sdk.so library used by… | |
| Aplazada | Media (6.8) | 0.25% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a crafted payload triggering an unsafe memory write operation in the my_tcp_receive function implemented in the libv2_sdk.so… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the process_push_file function implemented in the libv2_sdk.so library used… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+3 | 2/4/2024 | 17/6/2026 | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the pull_file_v2_proc function implemented in the libv2_sdk.so library used… |