Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.35%—Wolfssl9/4/202617/6/2026
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, which could cause…
AnalizadaAlta (8.3)0.59%—Wolfssl9/4/202617/6/2026
Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
ModificadaAlta (7)0.25%—Wolfssl9/4/20262/7/2026
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.
AnalizadaMedia (6.3)0.22%—Wolfssl9/4/202617/6/2026
Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate internally due to incorrect size handling of the AuthorityKeyIdentifier extension.
AnalizadaMedia (6)0.30%—Wolfssl9/4/202617/6/2026
In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and passes the caller-supplied IV verbatim to the MagicCrypto SDK with no internal counter, and because the explicit IV is zero-initialized at…
ModificadaCrítica (9.3)0.27%—Wolfssl9/4/202617/6/2026
Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key…
AnalizadaBaja (2.3)0.48%—Wolfssl9/4/202617/6/2026
Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte out-of-bounds write when outSz equals 1. Second, multiple callers pass sizeof(decOid) (64…
AnalizadaAlta (8.5)0.21%—Ufrisk Memprocfs8/4/202624/7/2026
MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An attacker who places a malicious DLL or shared…
AnalizadaAlta (7.8)0.13%—Dell Powerscale Onefs8/4/202624/7/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AnalizadaMedia (4.4)0.16%—Dell Powerscale Onefs8/4/202624/7/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
AplazadaMedia (6.5)0.22%—Elfsight Whatsapp Chat CCAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0.
AplazadaMedia (5.9)0.24%—Fesomia FSM Custom Featured Image CaptionAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fesomia FSM Custom Featured Image Caption fsm-custom-featured-image-caption allows DOM-Based XSS.This issue affects FSM Custom Featured Image Caption: from n/a through <= 1.25.1.
AnalizadaMedia (5.3)0.28%—Rustfs7/4/202624/7/2026
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an attacker-controlled…
AnalizadaAlta (8.8)0.28%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/20267/10/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
AnalizadaMedia (6.9)0.55%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.
AnalizadaAlta (8.6)0.67%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
AnalizadaAlta (8.7)0.51%—Buffalo Wzr-s900dhp FirmwareBuffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p Firmware+4227/3/202617/6/2026
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.
AnalizadaAlta (8.7)0.48%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.
AnalizadaAlta (8.6)1.4%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
Pendiente de análisisMedia (6.5)0.81%—Kubernetes CSI Driver FOR NFSAI20/3/202617/6/2026
A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During…
AnalizadaBaja (1.2)0.13%—Wolfssl19/3/202617/6/2026
1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted content. Note that…
AnalizadaBaja (1.3)0.59%—Wolfssl19/3/202617/6/2026
Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC public key point. The WOLFSSL_KCAPI_ECC code path copies the input to key->pubkey_raw (132…
AnalizadaMedia (6.9)0.77%—Wolfssl19/3/202617/6/2026
Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client program crash. This…
AnalizadaAlta (8.3)0.55%—Wolfssl19/3/202617/6/2026
Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.
AnalizadaAlta (7.5)0.44%—Wolfssl19/3/202617/6/2026
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of…