Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.6)0.29%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network…
AplazadaBaja (3)0.21%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the sdk_printf function implemented in the libv2_sdk.so…
AplazadaMedia (6.8)0.24%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in…
AplazadaMedia (6.8)0.24%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_receive_session_packet_ack function implemented in the libv2_sdk.so library used by…
AplazadaMedia (6.8)0.25%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a crafted payload triggering an unsafe memory write operation in the my_tcp_receive function implemented in the libv2_sdk.so…
AplazadaBaja (3)0.21%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the process_push_file function implemented in the libv2_sdk.so library used…
AplazadaBaja (3)0.21%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the pull_file_v2_proc function implemented in the libv2_sdk.so library used…