Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Nasa CryptolibAI | 17/9/2026 | 18/9/2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. | |
| Aplazada | Media (5.5) | 0.48% | — | Nasa Earthdata-searchAI | 31/8/2026 | 1/9/2026 | A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery.… | |
| Aplazada | Media (5.5) | 0.47% | — | Nasa Earthdata-searchAI | 31/8/2026 | 1/9/2026 | A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Media (5.3) | 0.38% | — | Nasa CFSAI | 30/8/2026 | 1/9/2026 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is… | |
| Aplazada | Media (5.3) | 0.38% | — | Nasa CFSAINasa SBN TCP ModuleAI | 30/8/2026 | 1/9/2026 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was… | |
| Aplazada | Media (6.9) | 0.54% | — | Nasa TrickAI | 30/8/2026 | 31/8/2026 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is… | |
| Aplazada | Alta (7.5) | 1.1% | — | Nasa HypercpAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Nasa Fprime-gdsAI | 10/8/2026 | 28/8/2026 | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Nasa Ammos Asynchronous Network Management SystemAI | 5/8/2026 | 26/8/2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access… | |
| Pendiente de análisis | Crítica (9.1) | 0.50% | — | Nasa Core Flight SystemAI | 4/8/2026 | 31/8/2026 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nasa FprimeAI | 3/8/2026 | 9/9/2026 | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Nasa CFSAINasa Software BUS NetworkAI | 3/8/2026 | 31/8/2026 | A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | |
| Pendiente de análisis | Alta (7.5) | 0.38% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nasa FprimeAI | 3/8/2026 | 31/8/2026 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters. | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Nasa CFSAI | 3/8/2026 | 31/8/2026 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure. | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 30/7/2026 | 31/8/2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a… | |
| Analizada | Crítica (9.3) | 0.83% | — | Nasa AIT DSN | 29/7/2026 | 18/8/2026 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials.… | |
| Analizada | Crítica (9.3) | 0.79% | — | Nasa AIT GUI | 29/7/2026 | 18/8/2026 | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session… | |
| Aplazada | Crítica (9.1) | 0.86% | — | Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI | 21/7/2026 | 23/7/2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In… | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 16/7/2026 | 17/7/2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. | |
| Aplazada | Media (6.9) | 0.17% | — | Nasa OpenvspAI | 25/5/2026 | 23/7/2026 | NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition… |