Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.16% | — | QNX LibtraceparserAI | 29/7/2026 | 30/7/2026 | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets. | |
| Aplazada | Media (6.4) | 0.10% | — | QNX NeutrinoAI | 14/7/2026 | 15/7/2026 | TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel. | |
| Aplazada | Alta (7.4) | 0.14% | — | QNX NeutrinoAI | 14/7/2026 | 15/7/2026 | Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel. | |
| Aplazada | Media (6.2) | 0.15% | — | QNX NeutrinoAI | 14/7/2026 | 15/7/2026 | Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel. | |
| Aplazada | Media (6.2) | 0.13% | — | QNX NeutrinoAI | 13/1/2026 | 17/6/2026 | Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel. | |
| Analizada | Crítica (9.8) | 0.73% | — | Blackberry QNX Software Development Platform | 10/6/2025 | 17/6/2026 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. | |
| Analizada | Alta (7.5) | 0.57% | — | Blackberry QNX Software Development Platform | 14/1/2025 | 17/6/2026 | Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | |
| Analizada | Alta (7.5) | 0.44% | — | Blackberry QNX Software Development Platform | 14/1/2025 | 17/6/2026 | NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | |
| Analizada | Crítica (9.8) | 0.62% | — | Blackberry QNX Software Development Platform | 14/1/2025 | 17/6/2026 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. | |
| Analizada | Alta (7.5) | 0.37% | — | Blackberry QNX Software Development Platform | 14/1/2025 | 17/6/2026 | Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec. | |
| Analizada | Alta (7.5) | 0.37% | — | Blackberry QNX Software Development Platform | 14/1/2025 | 17/6/2026 | Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec. | |
| Analizada | Media (6.2) | 0.16% | — | Blackberry QNX Software Development Platform | 8/10/2024 | 17/6/2026 | NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process. | |
| Analizada | Crítica (9) | 0.52% | — | Blackberry QNX Software Development Platform | 11/6/2024 | 17/6/2026 | An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel NUC 9 PRO Compute Element Nuc9v7qnb FirmwareIntel NUC PRO Compute Element Nuc9v7qnx FirmwareIntel NUC 9 PRO KIT Nuc9v7qnb FirmwareIntel NUC 9 PRO KIT Nuc9v7qnx Firmware | 19/1/2024 | 17/6/2026 | Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.1) | 0.24% | — | Blackberry QNX Software Development Platform | 14/11/2023 | 17/6/2026 | Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+207 | 11/8/2023 | 17/6/2026 | Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.16% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+30 | 11/8/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.14% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+55 | 10/5/2023 | 17/6/2026 | Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Nuc10i3fnh FirmwareIntel Nuc10i3fnhf FirmwareIntel Nuc10i3fnhfa FirmwareIntel Nuc10i3fnhja Firmware+113 | 10/5/2023 | 17/6/2026 | Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element, Intel(R) NUC Extreme, Intel(R) NUC 12 Extreme… | |
| Modificada | Media (4.4) | 0.16% | — | Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+35 | 10/5/2023 | 17/6/2026 | Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+55 | 12/5/2022 | 17/6/2026 | Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+55 | 12/5/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+55 | 12/5/2022 | 17/6/2026 | Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Blackberry QNX MomenticsBlackberry QNX Software Development PlatformBlackberry QNX OS FOR MedicalBlackberry QNX OS FOR Safety | 10/3/2022 | 17/6/2026 | An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX… | |
| Modificada | Crítica (9.8) | 1.8% | — | Blackberry QNX Software Development Platform | 13/12/2021 | 17/6/2026 | A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process. |