Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.57% | — | Free5gcAI | 20/9/2026 | 21/9/2026 | A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name:… | |
| Aplazada | Media (6.9) | 0.54% | — | Free5gcAI | 15/9/2026 | 30/9/2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative accepts every non-empty string instead of… | |
| Aplazada | Alta (7.5) | 0.76% | — | Free5gcAI | 4/9/2026 | 14/9/2026 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | |
| Aplazada | Baja (3.7) | 0.45% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and XRES* with strings.EqualFold and logs… | |
| Aplazada | Alta (7.5) | 0.42% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by… | |
| Aplazada | Crítica (9.3) | 0.59% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBeatTimer ranges, mandatory profile fields, or nfServices.ipEndPoints… | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 1/9/2026 | An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request. | |
| Aplazada | Media (6.9) | 0.74% | — | Free5gcAI | 31/7/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in an… | |
| Aplazada | Baja (2.1) | 0.55% | — | Free5gc AMFAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit is publicly available and might… |