Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.45%—Trustedfirmware Trusted Firmware-mAIARM McubootAI30/7/202517/6/2026
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components…
AnalizadaAlta (7.1)0.16%—Beyondtrust Privilege Management FOR Windows28/7/202517/6/2026
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.
AnalizadaAlta (7.2)0.13%—Beyondtrust Privilege Management FOR Windows28/7/202517/6/2026
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
AnalizadaBaja (3.7)0.41%—Trustedfirmware Mbed TLS20/7/202517/6/2026
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
AnalizadaAlta (8.8)0.50%—Rustaurius Ultimate WP Mail16/7/202517/6/2026
The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including the password-reset…
AplazadaMedia (5.2)0.29%—Matrix Rust SDKAI10/7/202517/6/2026
The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that directly pass…
AnalizadaMedia (6.5)0.32%—Trustedfirmware Mbed TLS4/7/202517/6/2026
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_lms_import_public_key allows context-dependent attackers to…
AnalizadaMedia (4.9)0.16%—Trustedfirmware Mbed TLS4/7/202517/6/2026
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can induce a hardware hash…
AplazadaMedia (4.3)0.14%—Trust Payments Gateway FOR WoocommerceAI4/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2 allows Cross Site Request Forgery.This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a through <= 1.3.6.
AplazadaMedia (5.7)0.22%—Trustwallet Trust WalletAI1/7/202517/6/2026
Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.
AplazadaAlta (8.2)0.28%—Dejan Jasnic Trusty Whistleblowing SolutionAI27/6/202517/6/2026
Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusty Whistleblowing: from n/a through <= 2.0.1.
AplazadaMedia (5.7)0.93%💥 ExploitOnetrust SDKAI25/6/202517/6/2026
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.
AplazadaMedia (4.3)0.17%—Sangfor AtrustAI22/6/202517/6/2026
Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.
AplazadaMedia (5.9)0.73%—Trustyai ExplainabilityAI20/6/202517/6/2026
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy…
AplazadaAlta (7.1)0.34%—Rustaurius Ultimate ReviewsAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Reflected XSS.This issue affects Ultimate Reviews: from n/a through <= 3.2.14.
AnalizadaAlta (8.6)0.95%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support16/6/202517/6/2026
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
AplazadaMedia (4.9)0.37%—Matrix-rust-sdk Matrix-sdk-cryptoAIMatrix-rust-sdkAI10/6/202517/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the…
AplazadaAlta (7.1)0.20%—Rust UsersAI6/6/202517/6/2026
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.
AplazadaAlta (8.8)0.53%—Rustaurius Ultimate WP MailAI6/6/202517/6/2026
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This issue affects Ultimate WP Mail: from n/a through <= 1.3.5.
AnalizadaAlta (7.3)0.32%—Sangfor Atrust24/5/202517/6/2026
A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library MSASN1.dll. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The complexity of an attack is…
AnalizadaAlta (7.5)0.60%💥 PoCTrustwave Modsecurity21/5/202517/6/2026
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule…
AplazadaMedia (5.7)0.14%—Intel Xeon 6 Processor With E-coresAIIntel Trust Domain ExtensionsAIIntel Software Guard ExtensionsAI13/5/202517/6/2026
Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.3)1.0%—Rust RingAIQuicAI9/5/202530/6/2026
A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.
AplazadaAlta (8.5)0.34%—Rustaurius Ultimate WP MailAI7/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows SQL Injection.This issue affects Ultimate WP Mail: from n/a through <= 1.3.4.
AplazadaMedia (5.4)0.16%—Rustaurius Ultimate WP MailAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Cross Site Request Forgery.This issue affects Ultimate WP Mail: from n/a through <= 1.3.4.
Orbitaley — Vulnerabilidades