Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Neurons FOR Zero-trust Access31/1/20244/8/2026
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
ModificadaAlta (7.5)1.1%—ARM Mbed TLSTrustedfirmware Mbed TLS31/1/202417/6/2026
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
ModificadaMedia (5.5)0.31%—ARM Mbed TLSTrustedfirmware Mbed TLS31/1/202417/6/2026
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in…
ModificadaAlta (7.5)0.69%—Trustedfirmware Mbed TLS21/1/202417/6/2026
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
ModificadaCrítica (9.8)0.65%—Rust-vmm Vmm-sys-util2/1/202417/6/2026
vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starting in version 0.5.0 and prior to version 0.12.0, an issue in the `FamStructWrapper::deserialize` implementation provided by the crate for `vmm_sys_util::fam::FamStructWrapper` can lead to out of…
ModificadaMedia (6.7)0.18%—Beyondtrust Privilege Management FOR Windows25/12/202317/6/2026
The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.
ModificadaAlta (7.8)0.23%—Beyondtrust Privilege Management FOR Windows12/12/202317/6/2026
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.
ModificadaAlta (7.8)0.14%—Beyondtrust Privilege Management FOR Windows12/12/202317/6/2026
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be…
ModificadaAlta (7.8)0.26%—Beyondtrust Privilege Management FOR Windows12/12/202317/6/2026
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFiles(x86)% environment variable. However, when this same policy gets pushed to a 32bit machine, this…
ModificadaAlta (7.8)0.22%—Beyondtrust Privilege Management FOR Windows12/12/202317/6/2026
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.
ModificadaAlta (8.8)0.64%—Beyondtrust Privilege Management FOR MAC11/12/202317/6/2026
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave…
ModificadaAlta (8.8)0.77%—Beyondtrust Privilege Management FOR Windows11/12/202317/6/2026
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When Avecto elevates the process, it removes the user who is launching the process, but not the second user. Therefore this…
ModificadaMedia (5.9)0.61%—Rustcrypto RSA28/11/202317/6/2026
RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. There is currently no fix available.…
ModificadaMedia (4.3)0.20%—Trustedindex Widgets FOR Google Reviews18/10/202317/6/2026
The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unauthenticated attackers to reset plugin settings and remove reviews…
ModificadaAlta (7.8)0.19%—Beyondtrust Privileged Remote Access12/10/202317/6/2026
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
ModificadaCrítica (9.8)1.1%—Trustedfirmware Mbed TLS7/10/202317/6/2026
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
ModificadaAlta (7.5)0.79%—ARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora7/10/202317/6/2026
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
ModificadaAlta (8.8)0.27%—Trustindex WP Testimonials3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Trustindex.Io WP Testimonials plugin <= 1.4.2 versions.
ModificadaMedia (6.7)0.39%—Trustedfirmware Op-tee15/9/202317/6/2026
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20 and prior to version 3.22, `shdr_verify_signature` can make a double free. `shdr_verify_signature` used to verify a TA binary before…
ModificadaAlta (7.5)0.39%—Trustedfirmware Trusted Firmware-m8/9/202317/6/2026
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the…
ModificadaCrítica (9.8)1.8%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support5/9/202317/6/2026
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating…
ModificadaAlta (8.8)1.1%—Virustotal Yara28/8/202317/6/2026
Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.
ModificadaMedia (6.1)0.90%—Rust-lang Rust24/8/202317/6/2026
Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in the report generated by `cargo build --timings`. A malicious package included as a dependency may inject nearly arbitrary HTML here,…
ModificadaAlta (7.3)0.70%💥 PoCRust-lang CargoFedoraproject Fedora4/8/202317/6/2026
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local…
ModificadaCrítica (9.8)1.1%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow.