Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.18% | — | Biostar Bios Update UtilityAI | 21/9/2026 | 22/9/2026 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been… | |
| Aplazada | Alta (8.5) | 0.18% | — | Biostar Temperature Monitor UtilityAI | 21/9/2026 | 21/9/2026 | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Uutils CoreutilsAI | 18/9/2026 | 22/9/2026 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when… | |
| Pendiente de análisis | Alta (8.2) | 0.19% | — | Dell Server Update UtilityAI | 17/9/2026 | 19/9/2026 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Utilities Network Management SystemAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily… | |
| Aplazada | Alta (8.2) | 0.34% | — | Oracle Utilities Network Management SystemAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 15/9/2026 | 17/9/2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available… | |
| Analizada | Baja (1.9) | 0.19% | — | GNU Binutils | 14/9/2026 | 21/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has… | |
| Analizada | Baja (0.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer… | |
| Analizada | Baja (1.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was… | |
| Analizada | Baja (1.9) | 0.21% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI | 9/9/2026 | 10/9/2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.66% | — | Java-json-tools Jackson-coreutilsAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack… | |
| Pendiente de análisis | Alta (8.5) | 0.22% | — | Util-linuxAI | 3/9/2026 | 24/9/2026 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Util-linuxAI | 2/9/2026 | 4/9/2026 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets… | |
| Pendiente de análisis | Alta (7.9) | 0.19% | — | Util-linuxAI | 2/9/2026 | 5/9/2026 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled… |