Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.17% | — | ARM Trusted Firmware-mAIInfineon Psoc64AIRaspberrypi Rp2350AI | 26/8/2026 | 9/9/2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | Infineon Airoc Wifi DriverAI | 22/8/2026 | 26/8/2026 | The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but… | |
| Aplazada | Alta (8.6) | 0.46% | — | QTI NeonAI | 28/7/2026 | 30/7/2026 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No… | |
| Aplazada | Alta (7.5) | 0.38% | — | Vertim Neon Channel Product Customizer FreeAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Neon Channel Product Customizer Free: from n/a through <= 2.0. | |
| Analizada | Media (5.4) | 0.21% | — | Flytxt Neon-dx | 12/5/2025 | 17/6/2026 | An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Vertim Neon Product Designer FOR WoocommerceAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0. | |
| Aplazada | Alta (8.5) | 0.40% | — | Vertim Neon Product DesignerAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0. | |
| Modificada | Media (5.4) | 0.52% | — | Eralion Neon Text | 27/10/2023 | 17/6/2026 | The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write… | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability… | |
| Modificada | Media (6.1) | 2.7% | — | Onlineonly Phpjabbers Appointment Scheduler | 15/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (5.4) | 0.55% | — | Laborator Neon | 27/8/2020 | 17/6/2026 | Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab. | |
| Modificada | Media (5.4) | 0.55% | — | Laborator Neon | 6/6/2020 | 17/6/2026 | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard. | |
| Modificada | Media (6.1) | 5.0% | — | Laborator Neon | 30/12/2019 | 17/6/2026 | An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter. | |
| Modificada | Media (5.9) | 0.85% | — | Banconeon Neon | 17/1/2018 | 17/6/2026 | The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 9.8% | — | Infineon Trusted Platform FirmwareInfineon RSA Library | 16/10/2017 | 17/6/2026 | The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection… | |
| Modificada | Media (6.6) | 0.54% | — | Infineon S-gold 2 PMB 8876 | 7/8/2017 | 17/6/2026 | A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti… | |
| Modificada | Alta (8.8) | 2.2% | — | Infineon S-gold 2 PMB 8876 | 7/8/2017 | 17/6/2026 | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60… | |
| Modificada | Media (5.8) | 1.5% | — | Webdav NeonApple MAC OS XCanonical Ubuntu LinuxFedoraproject Fedora | 21/8/2009 | 16/6/2026 | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification… | |
| Modificada | Media (4.3) | 8.4% | — | Webdav Neon | 21/8/2009 | 16/6/2026 | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Media (4.3) | 2.3% | — | Webdav Neon | 27/8/2008 | 16/6/2026 | neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function. | |
| Modificada | Alta (10) | 3.8% | — | Neon Labs Website | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter. | |
| Modificada | Alta (7.8) | 2.2% | — | Neon | 9/1/2007 | 16/6/2026 | Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a… | |
| Modificada | Alta (7.5) | 8.0% | — | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users. | |
| Modificada | Alta (7.5) | 8.0% | — | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter. |