Vulnerabilities

Summary — last 7 days

New vulnerabilities2,531▼ 362 vs. last week
Critical / high1,340▲ 76 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.1)0.21%—Ledger Nano XAILedger FlexAILedger StaxAI5/19/20267/24/2026
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause…
ModifiedLow (2.4)0.35%—Ledger Nano S FirmwareLedger Nano X Firmware8/10/20196/17/2026
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage…