Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow.
ModificadaCrítica (9.8)0.93%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow.
ModificadaCrítica (9.8)0.93%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow.
ModificadaCrítica (9.8)0.93%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow.
ModificadaCrítica (9.8)0.93%—Widevine Trusted Application26/6/202317/6/2026
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultant buffer overflow.
ModificadaMedia (5.9)1.0%💥 PoCTrustwallet Trust Wallet Browser ExtensionTrustwallet Trust Wallet Core27/4/202317/6/2026
Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only…
ModificadaAlta (7.5)1.2%—Bestools Trusted Tools Free Music14/4/202317/6/2026
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
ModificadaAlta (7.8)0.15%—Dell Trusted Device Agent6/4/202317/6/2026
Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges.
ModificadaAlta (7.8)1.3%—Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+828/2/202317/6/2026
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it…
ModificadaMedia (5.5)5.6%—Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+828/2/202317/6/2026
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
ModificadaMedia (5.4)0.51%—Trustindex Widgets FOR Google Reviews30/1/202317/6/2026
The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaAlta (7.5)0.91%—Trustwave ModsecurityDebian Linux20/1/202317/6/2026
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.
ModificadaAlta (7.5)1.2%—Owasp ModsecurityTrustwave ModsecurityDebian Linux20/1/202317/6/2026
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
ModificadaMedia (4.7)0.16%—ARM Mbed TLSTrustedfirmware Mbed TLS17/1/202317/6/2026
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave…
ModificadaAlta (7.4)0.63%—Trustedfirmware Trusted Firmware-a16/1/202317/6/2026
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
ModificadaMedia (5.9)0.65%—Rust-lang Cargo11/1/202317/6/2026
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust…
ModificadaMedia (6.4)0.42%—Trustedfirmware Op-tee19/12/202217/6/2026
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted applications via electromagnetic fault injections.
ModificadaCrítica (9.8)1.2%—ARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora15/12/202217/6/2026
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
ModificadaMedia (5.3)0.82%—ARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora15/12/202217/6/2026
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation,…
ModificadaAlta (7.5)2.7%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure5/12/202217/6/2026
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
ModificadaAlta (7.5)2.7%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure5/12/202217/6/2026
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
AnalizadaAlta (8.8)0.49%💥 PoCTrustedfirmware Op-tee29/11/202217/6/2026
OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and `entry_open_session()`. The commands…
ModificadaAlta (7.5)0.62%—Matrix-rust-sdk29/9/202217/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software…
ModificadaMedia (6.5)0.95%—Rust-lang Cargo14/9/202217/6/2026
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternate registry a specially crafted package that extracts way more data than its size (also known as a "zip bomb"),…
ModificadaAlta (8.1)1.2%—Rust-lang Cargo14/9/202217/6/2026
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it builds. To record when an extraction is successful, Cargo writes "ok" to the .cargo-ok file at the root of the…
Orbitaley — Vulnerabilidades