Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.16% | — | Ros2AI | 28/9/2026 | 30/9/2026 | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Openrobotics Ros2AIOpenrobotics Nav2AI | 5/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` . | |
| Aplazada | Alta (7.5) | 0.53% | — | Openrobotics Ros2AIOpenrobotics Nav2AI | 5/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Openrobotics Ros2AIOpenrobotics Nav2AI | 5/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file. | |
| Aplazada | Alta (7.3) | 0.30% | — | Open Robotic Ros2AIOpen Robotic Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Openrobotics Ros2AIOpenrobotics Nav2AI | 5/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file. | |
| Aplazada | Alta (7.3) | 0.31% | — | Open Robotic Operating System Ros2AIOpen Robotic Operating System Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process | |
| Modificada | Media (5.3) | 2.1% | — | Sros2 | 6/12/2019 | 17/6/2026 | SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2.) | |
| Modificada | Media (5.3) | 1.5% | — | Sros2 | 6/12/2019 | 17/6/2026 | SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2) leaks node information due to a leaky default configuration as indicated in the policy/defaults/dds/governance.xml document. |