Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.57%—Free5gcAI20/9/202621/9/2026
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name:…
AplazadaMedia (6.9)0.54%—Free5gcAI15/9/202630/9/2026
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative accepts every non-empty string instead of…
AplazadaAlta (7.5)0.76%—Free5gcAI4/9/202614/9/2026
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
AplazadaBaja (3.7)0.45%—Free5gcAI28/8/20268/9/2026
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and XRES* with strings.EqualFold and logs…
AplazadaAlta (7.5)0.42%—Free5gcAI28/8/20268/9/2026
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by…
AplazadaCrítica (9.3)0.59%—Free5gcAI28/8/20268/9/2026
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBeatTimer ranges, mandatory profile fields, or nfServices.ipEndPoints…
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/20261/9/2026
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request.
AplazadaAlta (7.5)0.46%—Free5gcAI27/8/202631/8/2026
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
AplazadaMedia (6.9)0.74%—Free5gcAI31/7/20268/9/2026
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in an…
AplazadaBaja (2.1)0.55%—Free5gc AMFAI4/7/20266/7/2026
A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit is publicly available and might…