Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.81% | — | Trustedfirmware Trusted Firmware-mAI | 9/10/2024 | 17/6/2026 | An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer pointer and a buffer length field. After a… | |
| Analizada | Alta (7.5) | 0.82% | — | Trustwave Modsecurity | 9/10/2024 | 17/6/2026 | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large… | |
| Aplazada | Media (6.5) | 0.27% | — | Trustmary Review & Testimonial WidgetsAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Trustmary Review & testimonial widgets trustmary allows Stored XSS.This issue affects Review & testimonial widgets: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.6) | 0.11% | — | Entrust Instant Financial IssuanceAI | 23/9/2024 | 17/6/2026 | Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software.… | |
| Aplazada | Media (5.9) | 0.20% | — | Entrust Instant Financial IssuanceAI | 23/9/2024 | 17/6/2026 | Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct… | |
| Modificada | Crítica (9.8) | 0.39% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have… | |
| Analizada | Crítica (9.8) | 0.68% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in… | |
| Modificada | Media (5.1) | 0.24% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and… | |
| Modificada | Media (4.7) | 0.29% | — | Trustedfirmware Trusted Firmware-m | 5/9/2024 | 17/6/2026 | An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function. | |
| Analizada | Alta (8.8) | 0.74% | — | Rust-lang Rust | 4/9/2024 | 17/6/2026 | Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust version 1.81.0, it was possible to bypass the fix when the batch file name had trailing whitespace or periods (which are ignored… | |
| Aplazada | Media (6.5) | 0.48% | — | RustixAI | 26/8/2024 | 17/6/2026 | Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Combined with a memory over-allocation issue in `rustix::fs::Dir::read_more`, this can cause quick and unbounded memory… | |
| Modificada | Alta (7.5) | 0.63% | — | Rust-bitcoin Miniscript | 19/8/2024 | 17/6/2026 | The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth. | |
| Aplazada | Media (5.9) | 0.27% | — | Virustran Button Contact VRAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.3. | |
| Analizada | Media (5.8) | 0.16% | — | AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a | 13/8/2024 | 17/6/2026 | Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service. | |
| Aplazada | Alta (8.4) | 0.59% | 💥 PoC | Entrustdatacard XPS Card Printer DriverAI | 22/7/2024 | 17/6/2026 | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload. | |
| Aplazada | Media (5.4) | 0.28% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 18/7/2024 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value… | |
| Aplazada | Media (5.3) | 0.42% | — | Trustedlogin VendorAI | 10/7/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1. | |
| Aplazada | Alta (8.6) | 0.71% | — | Rust-phonenumberAI | 9/7/2024 | 17/6/2026 | phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted… | |
| Modificada | Media (6.7) | 0.22% | — | Renesas Arm-trusted-firmware | 8/7/2024 | 17/6/2026 | Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot. | |
| Modificada | Media (6.7) | 0.21% | — | Renesas Arm-trusted-firmware | 8/7/2024 | 17/6/2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program files https://github.Com/renesas-rcar/arm-trusted-firmware/blob/rcar_gen3_v2.5/drivers/renesas/common/io/i...… | |
| Analizada | Alta (7.5) | 0.28% | — | Mongodb Rust Driver | 2/7/2024 | 17/6/2026 | Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 | |
| Aplazada | Media (4.3) | 0.33% | — | Trustedcomputinggroup Tpm2 Software StackAI | 28/6/2024 | 17/6/2026 | This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the… | |
| Analizada | Media (4.9) | 0.41% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response. | |
| Analizada | Baja (2.7) | 0.27% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+9 | 10/6/2024 | 17/6/2026 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell… |