Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.59% | — | Sonos TractAI | 18/8/2026 | 20/8/2026 | A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 1.1% | — | Sonos ERA 300 Firmware | 11/4/2026 | 17/6/2026 | Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the… | |
| Aplazada | Media (5.5) | 2.2% | — | Jishi Node-sonos-http-apiAI | 17/2/2026 | 17/6/2026 | A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the file lib/tts-providers/mac-os.js of the component TTS Provider. This manipulation of the argument phrase causes os command injection. It is possible to initiate the attack… | |
| Analizada | Alta (8.8) | 0.38% | — | Sonos ERA 300 Firmware | 2/6/2025 | 17/6/2026 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of ALAC data. The… | |
| Analizada | Alta (8.8) | 0.42% | — | Sonos S2 | 23/4/2025 | 17/6/2026 | Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HLS playlist data.… | |
| Analizada | Alta (8.8) | 0.42% | — | Sonos S1Sonos S2 | 23/4/2025 | 17/6/2026 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of ID3 data. The… | |
| Analizada | Alta (8.8) | 0.54% | — | Sonos S1Sonos S2 | 23/4/2025 | 17/6/2026 | Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Baja (3.4) | 0.22% | — | Api.sonos.comAI | 21/4/2025 | 17/6/2026 | Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC 6819 section 5.2.3.5. An authorization code may be sent to an attacker-controlled destination. This might have further implications… | |
| Aplazada | Media (6) | 0.79% | — | Sonos Play5 GEN 2AISonos PlaybaseAISonos Play 1AISonos ONEAI+2 | 12/8/2024 | 17/6/2026 | In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow persistent arbitrary code execution with Linux kernel privileges. A failure to correctly handle the return value of the setenv command can be used to override the… | |
| Aplazada | Alta (7.8) | 0.39% | — | Sonos AMPAISonos ARCAISonos ARC SLAISonos BeamAI+3 | 12/8/2024 | 17/6/2026 | In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel.… | |
| Modificada | Alta (8.8) | 1.2% | — | Sonos ERA 100 Firmware | 6/6/2024 | 17/6/2026 | Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Modificada | Media (6.5) | 0.46% | — | Sonos ERA 100 Firmware | 6/6/2024 | 17/6/2026 | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Modificada | Alta (8.8) | 0.74% | — | Sonos ERA 100 Firmware | 6/6/2024 | 17/6/2026 | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Modificada | Media (4.3) | 0.42% | — | Sonos ERA 100 Firmware | 6/6/2024 | 17/6/2026 | Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Modificada | Alta (8.8) | 0.81% | — | Sonos ONE FirmwareSonos S1Sonos S2 | 20/4/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPEG-TS parser. The issue results from the lack of proper validation of the length… | |
| Modificada | Media (6.5) | 0.63% | — | Sonos ONE FirmwareSonos S1Sonos S2 | 20/4/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issue results from the… | |
| Modificada | Media (6.5) | 0.63% | — | Sonos ONE FirmwareSonos S1Sonos S2 | 20/4/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msprox endpoint. The issue results from the lack of proper validation of… | |
| Modificada | Alta (8.8) | 0.78% | — | Sonos ONE FirmwareSonos S1Sonos S2 | 20/4/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issue results from the lack of… | |
| Modificada | Media (6.8) | 0.48% | — | Sonos ONE Firmware | 20/10/2022 | 17/6/2026 | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device. | |
| Modificada | Crítica (9.8) | 7.2% | — | Sonos S1Sonos S2 | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within the ALAC audio codec. The issue results… | |
| Modificada | Alta (8.8) | 4.1% | — | Sonos S1Sonos S2 | 18/2/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within the anacapd daemon. The issue… | |
| Modificada | Crítica (9.6) | 1.3% | — | Sonos Firmware | 3/7/2018 | 17/6/2026 | The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker. |