Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.56%—Nasa CryptolibAI17/9/202618/9/2026
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
AplazadaMedia (5.5)0.48%—Nasa Earthdata-searchAI31/8/20261/9/2026
A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery.…
AplazadaMedia (5.5)0.47%—Nasa Earthdata-searchAI31/8/20261/9/2026
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is…
AplazadaMedia (5.3)0.38%—Nasa CFSAI30/8/20261/9/2026
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is…
AplazadaMedia (5.3)0.38%—Nasa CFSAINasa SBN TCP ModuleAI30/8/20261/9/2026
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was…
AplazadaMedia (6.9)0.54%—Nasa TrickAI30/8/202631/8/2026
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is…
AplazadaAlta (7.5)1.1%—Nasa HypercpAI10/8/202628/8/2026
An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation.
AplazadaCrítica (9.8)1.3%—Nasa Fprime-gdsAI10/8/202628/8/2026
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.
AplazadaCrítica (9.8)0.68%—Nasa Ammos Asynchronous Network Management SystemAI5/8/202626/8/2026
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access…
Pendiente de análisisCrítica (9.1)0.50%—Nasa Core Flight SystemAI4/8/202631/8/2026
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
Pendiente de análisisAlta (7.5)0.46%—Nasa CFSAI3/8/202631/8/2026
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
AplazadaAlta (7.5)0.49%—Nasa FprimeAI3/8/20269/9/2026
An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Pendiente de análisisAlta (7.5)0.36%—Nasa CFSAI3/8/202631/8/2026
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.
Pendiente de análisisAlta (7.5)0.53%—Nasa CFSAINasa Software BUS NetworkAI3/8/202631/8/2026
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
Pendiente de análisisAlta (7.5)0.49%—Nasa CFSAI3/8/202631/8/2026
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
Pendiente de análisisAlta (7.5)0.39%—Nasa CFSAI3/8/202631/8/2026
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
Pendiente de análisisAlta (7.5)0.38%—Nasa CFSAI3/8/202631/8/2026
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
AplazadaAlta (7.5)0.49%—Nasa FprimeAI3/8/202631/8/2026
The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.
Pendiente de análisisAlta (7.5)0.44%—Nasa CFSAI3/8/202631/8/2026
An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI30/7/202631/8/2026
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a…
AnalizadaCrítica (9.3)0.83%—Nasa AIT DSN29/7/202618/8/2026
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials.…
AnalizadaCrítica (9.3)0.79%—Nasa AIT GUI29/7/202618/8/2026
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session…
AplazadaCrítica (9.1)0.86%—Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI21/7/202623/7/2026
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In…
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI16/7/202617/7/2026
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
AplazadaMedia (6.9)0.17%—Nasa OpenvspAI25/5/202623/7/2026
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition…