Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisCrítica (9.8)0.61%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
En análisisAlta (7.7)0.24%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has…
En análisisAlta (7.5)0.31%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
En análisisAlta (7.8)0.14%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote…
En análisisAlta (8.8)0.18%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
En análisisAlta (7.5)0.31%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
En análisisAlta (8.6)0.32%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
En análisisAlta (8.6)0.27%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
En análisisAlta (7.5)0.26%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
En análisisAlta (7.5)0.31%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
Pendiente de análisisAlta (7)0.17%—Draeger Zeus Infinity EmpoweredAIDraeger Zeus RS C500AIDraeger Service ConnectAI2/6/202622/7/2026
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy…
Pendiente de análisisAlta (8.8)0.16%—Draeger Infinity Acute Care SystemAIDraeger Infinity M540AI2/6/202622/7/2026
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can…
Pendiente de análisisAlta (7.1)0.18%—Draeger Infinity M300AI2/6/202622/7/2026
Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to the hospital or Infinity Network to repeatedly trigger device reboots until the device enters a fail state requiring manual restart. Attackers…
Pendiente de análisisAlta (7.1)0.19%—Draeger Infinity M300AI2/6/202622/7/2026
Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly trigger device reboots by sending malicious requests over the Infinity Network. Attackers can exploit this vulnerability to…
Pendiente de análisisAlta (8.8)0.13%—Draeger Infinity Acute Care SystemAIDraeger Infinity M540AI2/6/202622/7/2026
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an…
AnalizadaMedia (5.3)0.20%—Draeger Infinity Delta FirmwareDraeger Delta XL FirmwareDraeger Kappa Firmware2/6/202622/7/2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the…
AnalizadaAlta (8.6)0.12%—Draeger Infinity Explorer C700 Firmware1/6/202622/7/2026
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display…
AnalizadaAlta (7.1)0.41%—Draeger Infinity Delta FirmwareDraeger Delta XL FirmwareDraeger Kappa Firmware1/6/202622/7/2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to…
AnalizadaMedia (5.3)0.31%—Pexip Infinity25/12/202517/6/2026
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
AnalizadaAlta (7.5)0.25%—Pexip Infinity25/12/202517/6/2026
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
AnalizadaAlta (7.5)0.31%—Pexip Infinity25/12/202517/6/2026
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
AnalizadaAlta (7.5)0.31%—Pexip Infinity25/12/202517/6/2026
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.
AnalizadaAlta (7.5)0.42%—Pexip Infinity25/12/202517/6/2026
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.
AnalizadaAlta (7.5)0.37%—Pexip Infinity25/12/202530/9/2026
Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.
AnalizadaAlta (7.5)0.21%—Pexip Infinity25/12/202530/9/2026
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.