Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.67%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.
Pendiente de análisisMedia (5.2)0.32%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and…
Pendiente de análisisMedia (5.3)0.34%—Core-moosAI3/9/202614/9/2026
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
Pendiente de análisisAlta (7.1)0.36%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the…
Pendiente de análisisAlta (8.7)0.63%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.
Pendiente de análisisAlta (8.7)0.63%—Core-moosAI3/9/202614/9/2026
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block…
Pendiente de análisisAlta (8.7)0.77%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Attackers can send packets with large declared lengths to exhaust server memory and cause denial of…
Pendiente de análisisAlta (8.7)0.66%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB port, causing an unhandled exception that terminates the database process.
Pendiente de análisisCrítica (9.3)1.0%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to…
Pendiente de análisisAlta (8.8)0.51%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting…
Pendiente de análisisCrítica (9.3)0.82%—Core-moosAI3/9/202614/9/2026
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and…
Pendiente de análisisCrítica (9.3)0.82%—Core-moosAI3/9/20268/9/2026
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations…
AnalizadaAlta (7.5)0.39%—Web3js Web3-core-method24/9/202517/6/2026
web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS)…
AplazadaCrítica (9.8)0.51%—Coresmartcontracts UniswapAI29/4/202517/6/2026
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function
ModificadaAlta (8)0.40%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaBaja (3.5)0.30%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
ModificadaAlta (8)0.35%—Intel Celeron J6413 FirmwareIntel Celeron N6211 FirmwareIntel Pentium J6425 FirmwareIntel Pentium N6415 Firmware+29411/8/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
ModificadaMedia (4.4)0.17%—Intel Pentium J6426 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+90211/8/202317/6/2026
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.5)3.0%—Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+53011/8/202317/6/2026
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.18%—Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+46310/5/202317/6/2026
Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.25%—Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+26910/5/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.36%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8260l Firmware+48818/8/202217/6/2026
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)5.0%—Intel Core I7-6500u FirmwareIntel Core I7-6510u FirmwareIntel Core I7-6560u FirmwareIntel Core I7-6567u Firmware+12512/7/202217/6/2026
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain…
ModificadaMedia (5.5)0.32%—Intel Xeon E3-1585 V5 FirmwareIntel Xeon E3-1585l V5 FirmwareIntel Xeon E3-1578l V5 FirmwareIntel Xeon E3-1575m V5 Firmware+40315/6/202217/6/2026
Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access.
ModificadaMedia (5.5)0.36%—Intel Celeron N6210 FirmwareIntel Celeron N4500 FirmwareIntel Celeron N4505 FirmwareIntel Celeron N5100 Firmware+39512/5/202217/6/2026
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.