Vulnerabilities
Summary — last 7 days
New vulnerabilities2,531▼ 362 vs. last week
Critical / high1,340▲ 76 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.1) | 0.21% | — | Ledger Nano XAILedger FlexAILedger StaxAI | 5/19/2026 | 7/24/2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause… | |
| Modified | Low (2.4) | 0.35% | — | Ledger Nano S FirmwareLedger Nano X Firmware | 8/10/2019 | 6/17/2026 | On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage… |