Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | — | — | Arista Cloudvision PortalAIArista Cloudvision SensorAI | 6/10/2026 | 6/10/2026 | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | |
| Pendiente de análisis | Alta (8.8) | 0.08% | — | Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI | 15/9/2026 | 18/9/2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.… | |
| Pendiente de análisis | Media (6.8) | 0.27% | — | Bosch Sensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}}… | |
| Pendiente de análisis | Alta (8) | 0.31% | — | Boschsensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | Bosch Bme690 SensorapiAI | 10/9/2026 | 10/9/2026 | An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping… | |
| Pendiente de análisis | Alta (8.4) | 0.19% | — | Bosch Sensortec Bhi385 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event… | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Bosch Sensortec Bhi360 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875).… | |
| Pendiente de análisis | Crítica (9.3) | 0.72% | — | Tenable Sensor ProxyAI | 3/8/2026 | 18/8/2026 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. | |
| Aplazada | Alta (8.8) | 0.14% | — | Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI | 22/7/2026 | 22/7/2026 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | AMD Sensor Fusion HUB DriverAI | 15/5/2026 | 17/6/2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash | |
| Pendiente de análisis | Media (6.2) | 0.11% | — | Ardupilot RoverAIArdupilot AP Inertialsensor Adis1647xAI | 13/5/2026 | 17/6/2026 | Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor component. | |
| Pendiente de análisis | Media (5.1) | 0.56% | — | Linkit Location Aware Sensor SystemAI | 19/3/2026 | 14/7/2026 | Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing… | |
| Aplazada | Alta (7.5) | 0.40% | — | Freyrsensors Freyrs ADA Iec-60870-5-104 ServerAI | 23/12/2025 | 17/6/2026 | FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific message sequences. | |
| Aplazada | Alta (7.6) | 0.32% | — | Silabs Z-wave PIR Sensor Reference DesignAISilabs SisdkAI | 31/10/2025 | 17/6/2026 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Crowdstrike Falcon Sensor FOR WindowsAI | 8/10/2025 | 17/6/2026 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is… | |
| Aplazada | Media (5.6) | 0.12% | — | Crowdstrike Falcon SensorAI | 8/10/2025 | 17/6/2026 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There… | |
| Aplazada | Alta (8.8) | 0.59% | — | Cyrisma SensorAI | 16/9/2025 | 17/6/2026 | CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM by replacing DataSpotliteAgent.exe or any other binaries called by the Cyrisma_Agent… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Brewlabs SensorpressAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPress allows Stored XSS. This issue affects SensorPress: from n/a through 1.0. | |
| Aplazada | Alta (8.5) | 0.18% | — | Ellipticlabs Virtual Lock SensorAI | 17/7/2025 | 17/6/2026 | An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges. | |
| Analizada | Alta (8.4) | 0.16% | — | Sensopart Visor Vision Sensors Firmware | 23/6/2025 | 17/6/2026 | An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges. | |
| Aplazada | Crítica (9.1) | 0.85% | — | Ksix Zigbee Gateway ModuleAIKsix Door SensorAIKsix Motion SensorAI | 15/4/2025 | 17/6/2026 | A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless… | |
| Aplazada | Baja (2.5) | 0.16% | — | Carbonblack Cloud Windows SensorAI | 5/3/2025 | 17/6/2026 | Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a vulnerability in software. | |
| Aplazada | Alta (8.1) | 0.26% | — | Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI | 12/2/2025 | 17/6/2026 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection… | |
| Aplazada | Alta (7.5) | 0.41% | — | Aesensors Ae1021AIAesensors Ae1021peAI | 18/12/2024 | 17/6/2026 | Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string. | |
| Analizada | Media (5.3) | 0.41% | — | Nissan-global Blind Spot Protection Sensor ECU Firmware | 19/8/2024 | 17/6/2026 | Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests. |