Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.60% | — | DJI Mavic Mini FirmwareDJI Spark FirmwareDJI Mini SE Firmware | 4/3/2026 | 17/6/2026 | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem | |
| Aplazada | Baja (1.3) | 0.41% | — | DJI Mavic MiniAIDJI Mavic AIRAIDJI SparkAIDJI Mavic Mini SEAI | 2/2/2026 | 17/6/2026 | A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within the local network.… | |
| Aplazada | Baja (1.3) | 0.24% | — | DJI Mavic SparkAIDJI Mavic AIRAIDJI Mavic MiniAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attacker needs to be present on the local network. A high complexity level is… | |
| Aplazada | Baja (3) | 0.21% | — | DJI Mavic Mini 3 PROAI | 2/4/2024 | 17/6/2026 | An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself. | |
| Aplazada | Media (5.2) | 0.24% | — | DJI Mavic Mini 3 PROAI | 2/4/2024 | 17/6/2026 | A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication. |