Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.45% | — | Trustedfirmware Trusted Firmware-mAIARM McubootAI | 30/7/2025 | 17/6/2026 | TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components… | |
| Analizada | Alta (7.1) | 0.16% | — | Beyondtrust Privilege Management FOR Windows | 28/7/2025 | 17/6/2026 | Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions. | |
| Analizada | Alta (7.2) | 0.13% | — | Beyondtrust Privilege Management FOR Windows | 28/7/2025 | 17/6/2026 | Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator. | |
| Analizada | Baja (3.7) | 0.41% | — | Trustedfirmware Mbed TLS | 20/7/2025 | 17/6/2026 | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. | |
| Analizada | Alta (8.8) | 0.50% | — | Rustaurius Ultimate WP Mail | 16/7/2025 | 17/6/2026 | The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including the password-reset… | |
| Aplazada | Media (5.2) | 0.29% | — | Matrix Rust SDKAI | 10/7/2025 | 17/6/2026 | The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that directly pass… | |
| Analizada | Media (6.5) | 0.32% | — | Trustedfirmware Mbed TLS | 4/7/2025 | 17/6/2026 | In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_lms_import_public_key allows context-dependent attackers to… | |
| Analizada | Media (4.9) | 0.16% | — | Trustedfirmware Mbed TLS | 4/7/2025 | 17/6/2026 | In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can induce a hardware hash… | |
| Aplazada | Media (4.3) | 0.14% | — | Trust Payments Gateway FOR WoocommerceAI | 4/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2 allows Cross Site Request Forgery.This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a through <= 1.3.6. | |
| Aplazada | Media (5.7) | 0.22% | — | Trustwallet Trust WalletAI | 1/7/2025 | 17/6/2026 | Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance. | |
| Aplazada | Alta (8.2) | 0.28% | — | Dejan Jasnic Trusty Whistleblowing SolutionAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusty Whistleblowing: from n/a through <= 2.0.1. | |
| Aplazada | Media (5.7) | 0.93% | 💥 Exploit | Onetrust SDKAI | 25/6/2025 | 17/6/2026 | An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability. | |
| Aplazada | Media (4.3) | 0.17% | — | Sangfor AtrustAI | 22/6/2025 | 17/6/2026 | Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command. | |
| Aplazada | Media (5.9) | 0.73% | — | Trustyai ExplainabilityAI | 20/6/2025 | 17/6/2026 | A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy… | |
| Aplazada | Alta (7.1) | 0.34% | — | Rustaurius Ultimate ReviewsAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Reflected XSS.This issue affects Ultimate Reviews: from n/a through <= 3.2.14. | |
| Analizada | Alta (8.6) | 0.95% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 16/6/2025 | 17/6/2026 | The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution. | |
| Aplazada | Media (4.9) | 0.37% | — | Matrix-rust-sdk Matrix-sdk-cryptoAIMatrix-rust-sdkAI | 10/6/2025 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the… | |
| Aplazada | Alta (7.1) | 0.20% | — | Rust UsersAI | 6/6/2025 | 17/6/2026 | A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list. | |
| Aplazada | Alta (8.8) | 0.53% | — | Rustaurius Ultimate WP MailAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This issue affects Ultimate WP Mail: from n/a through <= 1.3.5. | |
| Analizada | Alta (7.3) | 0.32% | — | Sangfor Atrust | 24/5/2025 | 17/6/2026 | A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library MSASN1.dll. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The complexity of an attack is… | |
| Analizada | Alta (7.5) | 0.60% | 💥 PoC | Trustwave Modsecurity | 21/5/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule… | |
| Aplazada | Media (5.7) | 0.14% | — | Intel Xeon 6 Processor With E-coresAIIntel Trust Domain ExtensionsAIIntel Software Guard ExtensionsAI | 13/5/2025 | 17/6/2026 | Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 1.0% | — | Rust RingAIQuicAI | 9/5/2025 | 30/6/2026 | A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received. | |
| Aplazada | Alta (8.5) | 0.34% | — | Rustaurius Ultimate WP MailAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows SQL Injection.This issue affects Ultimate WP Mail: from n/a through <= 1.3.4. | |
| Aplazada | Media (5.4) | 0.16% | — | Rustaurius Ultimate WP MailAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Cross Site Request Forgery.This issue affects Ultimate WP Mail: from n/a through <= 1.3.4. |