Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.26%—Beyondtrust Beyondinsight4/6/202417/6/2026
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
ModificadaCrítica (9.1)0.22%—Beyondtrust Beyondinsight4/6/202417/6/2026
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
AplazadaAlta (8.4)0.19%—Etrust HoraciusAI3/5/202417/6/2026
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.
AnalizadaMedia (4.3)0.49%—Redhat Trusted Profile Analyzer25/4/202417/6/2026
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
AnalizadaAlta (7.8)0.17%—Beyondtrust U-series Appliance19/4/202417/6/2026
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
AnalizadaAlta (7.8)0.17%—Beyondtrust U-series Appliance19/4/202417/6/2026
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
AplazadaAlta (7.5)0.95%—RustlsAI19/4/202417/6/2026
Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This…
AnalizadaCrítica (9.8)6.9%—Haskell Process LibraryNodejs Node.jsPHPRust-lang Rust+110/4/202417/6/2026
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
AnalizadaCrítica (10)20%💥 PoCFedoraproject FedoraRust-lang Rust9/4/202417/6/2026
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to control the arguments passed to the…
AplazadaMedia (5.9)0.41%—Rust-opensslAI4/4/202417/6/2026
A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects…
AnalizadaCrítica (9.1)0.74%—Trustedfirmware Mbed TLS3/4/202417/6/2026
In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.
AnalizadaMedia (5.4)0.41%—Trustedfirmware Mbed TLS3/4/202417/6/2026
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implementation of the protocol if it is disabled. If the TLS 1.2 implementation was disabled at build time, a TLS 1.2 client could put a TLS 1.3-only server into an infinite loop…
AnalizadaMedia (6.5)0.41%—Trustedfirmware Mbed TLS3/4/202417/6/2026
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially…
ModificadaAlta (8.2)0.85%—ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora29/3/202417/6/2026
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
AplazadaAlta (7.6)0.55%—Trustindex WP TestimonialsAI28/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.
AplazadaAlta (8)0.53%—Trustindex Widgets FOR Google ReviewsAI26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
AnalizadaAlta (7.5)0.73%—Trusteddomain Opendmarc26/2/202417/6/2026
OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
AplazadaMedia (4.4)0.22%—ARM Trusted Firmware-aAI21/2/202417/6/2026
Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the…
AnalizadaBaja (2)0.14%—Renesas Arm-trusted-firmware19/2/202417/6/2026
During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_descs”. For each image, the bl2 reads the image length and destination from the image’s certificate. Because of the way of reading from the image, which base on 32-bit unsigned integer value, it can…
AnalizadaCrítica (9.8)0.46%—IBM Trusteer Android SDK FOR MobileIBM Trusteer IOS SDK FOR Mobile17/2/202417/6/2026
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.
AnalizadaAlta (7.8)0.13%—Beyondtrust Privilege Management FOR Windows16/2/202417/6/2026
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.
AnalizadaBaja (3.3)0.16%—Beyondtrust Privilege Management FOR Windows16/2/202417/6/2026
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.
ModificadaAlta (8.3)95%💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway13/2/202417/6/2026
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
ModificadaAlta (7.5)0.55%—Binance Trust Wallet8/2/202417/6/2026
The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can…
ModificadaCrítica (9.8)0.51%—Rustdesk6/2/202417/6/2026
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures…