Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.67% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication. | |
| Pendiente de análisis | Media (5.2) | 0.32% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Core-moosAI | 3/9/2026 | 14/9/2026 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface. | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the… | |
| Pendiente de análisis | Alta (8.7) | 0.63% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability. | |
| Pendiente de análisis | Alta (8.7) | 0.63% | — | Core-moosAI | 3/9/2026 | 14/9/2026 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block… | |
| Pendiente de análisis | Alta (8.7) | 0.77% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Attackers can send packets with large declared lengths to exhaust server memory and cause denial of… | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process. | |
| Pendiente de análisis | Crítica (9.3) | 1.0% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to… | |
| Pendiente de análisis | Alta (8.8) | 0.51% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting… | |
| Pendiente de análisis | Crítica (9.3) | 0.82% | — | Core-moosAI | 3/9/2026 | 14/9/2026 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and… | |
| Pendiente de análisis | Crítica (9.3) | 0.82% | — | Core-moosAI | 3/9/2026 | 8/9/2026 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations… | |
| Analizada | Alta (7.5) | 0.39% | — | Web3js Web3-core-method | 24/9/2025 | 17/6/2026 | web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS)… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Coresmartcontracts UniswapAI | 29/4/2025 | 17/6/2026 | An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function | |
| Modificada | Alta (8) | 0.40% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Baja (3.5) | 0.30% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Alta (8) | 0.35% | — | Intel Celeron J6413 FirmwareIntel Celeron N6211 FirmwareIntel Pentium J6425 FirmwareIntel Pentium N6415 Firmware+294 | 11/8/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (4.4) | 0.17% | — | Intel Pentium J6426 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+902 | 11/8/2023 | 17/6/2026 | Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 3.0% | — | Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+530 | 11/8/2023 | 17/6/2026 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+463 | 10/5/2023 | 17/6/2026 | Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+269 | 10/5/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.36% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8260l Firmware+488 | 18/8/2022 | 17/6/2026 | Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 5.0% | — | Intel Core I7-6500u FirmwareIntel Core I7-6510u FirmwareIntel Core I7-6560u FirmwareIntel Core I7-6567u Firmware+125 | 12/7/2022 | 17/6/2026 | Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain… | |
| Modificada | Media (5.5) | 0.32% | — | Intel Xeon E3-1585 V5 FirmwareIntel Xeon E3-1585l V5 FirmwareIntel Xeon E3-1578l V5 FirmwareIntel Xeon E3-1575m V5 Firmware+403 | 15/6/2022 | 17/6/2026 | Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access. | |
| Modificada | Media (5.5) | 0.36% | — | Intel Celeron N6210 FirmwareIntel Celeron N4500 FirmwareIntel Celeron N4505 FirmwareIntel Celeron N5100 Firmware+395 | 12/5/2022 | 17/6/2026 | Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |