Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.11%—Mediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 FirmwareMediatek Mt6768 Firmware+321/6/202622/7/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.
AnalizadaMedia (6.4)0.08%—Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+321/6/202622/7/2026
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.
AnalizadaMedia (6.7)0.11%—Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+321/6/202622/7/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
ModificadaMedia (6.5)0.36%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+817/4/202517/6/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028;…