Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.8) | — | — | Windriver VxworksAI | 1/10/2026 | 2/10/2026 | An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with… | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 30/9/2026 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09 | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 29/9/2026 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09 | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Windriver VxworksAI | 28/9/2026 | 29/9/2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 28/9/2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Vxworks Mr-gm5l-s1AIVxworks Mr-gm5a-l1AI | 11/3/2026 | 17/6/2026 | Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration. | |
| Aplazada | Media (4.6) | 0.21% | — | Wind River Systems Vxworks 7AI | 21/3/2025 | 17/6/2026 | : Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation. Specifically crafted USB packets may lead to the system becoming unavailable This issue affects VxWorks 7: from 22.06 through 24.03. | |
| Aplazada | Media (4.3) | 0.25% | — | Windriver VxworksAI | 14/5/2024 | 17/6/2026 | A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09. | |
| Analizada | Alta (7.5) | 0.49% | — | Windriver Vxworks | 15/2/2024 | 17/6/2026 | An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak. | |
| Modificada | Alta (8.8) | 1.5% | — | Windriver Vxworks | 22/9/2023 | 17/6/2026 | An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from… | |
| Modificada | Alta (7.5) | 1.1% | — | Windriver Vxworks | 25/11/2022 | 17/6/2026 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure. | |
| Modificada | Alta (7.5) | 1.0% | — | Windriver Vxworks | 29/3/2022 | 17/6/2026 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario. | |
| Modificada | Media (6.5) | 0.88% | — | Windriver Vxworks | 24/11/2021 | 17/6/2026 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free. | |
| Modificada | Crítica (9.8) | 2.5% | — | Windriver VxworksOracle Communications Eagle | 12/5/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.8% | — | Windriver Vxworks | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. | |
| Modificada | Crítica (9.8) | 2.4% | — | Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+32 | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. | |
| Modificada | Media (5.3) | 1.0% | — | Windriver Vxworks | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. | |
| Modificada | Crítica (9.8) | 1.9% | — | Windriver VxworksSiemens Sgt-100 FirmwareSiemens Sgt-200 FirmwareSiemens Sgt-300 Firmware+4 | 11/3/2021 | 17/6/2026 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.3) | 1.6% | — | Windriver VxworksOracle Communications Eagle | 3/2/2021 | 17/6/2026 | In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption. | |
| Modificada | Alta (7.5) | 1.1% | — | Windriver Vxworks | 23/7/2020 | 17/6/2026 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. | |
| Modificada | Alta (7.5) | 1.4% | — | Windriver Vxworks | 27/4/2020 | 17/6/2026 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. | |
| Modificada | Crítica (9.8) | 4.1% | — | Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+3 | 14/8/2019 | 17/6/2026 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw). | |
| Modificada | Crítica (9.8) | 9.0% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. | |
| Modificada | Crítica (9.8) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. | |
| Modificada | Alta (7.5) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |