Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.86% | — | Rust-osdev Linked-list-allocator | 7/9/2022 | 17/6/2026 | linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialized with a size smaller than `3 * size_of::<usize>` because of… | |
| Modificada | Alta (7.5) | 1.9% | — | Rust-websocket Project Rust-websocketFedoraproject Fedora | 1/8/2022 | 17/6/2026 | Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would allocate a buffer based on the declared… | |
| Modificada | Crítica (9.1) | 2.3% | — | ARM Mbed TLSTrustedfirmware Mbed TLSDebian Linux | 15/7/2022 | 17/6/2026 | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on… | |
| Modificada | Media (6.1) | 0.74% | — | Ltgplc Rustici Software Scorm Engine | 9/6/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an… | |
| Modificada | Alta (8.8) | 0.99% | — | Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware | 7/4/2022 | 9/7/2026 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication. | |
| Modificada | Media (6.5) | 0.60% | — | Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware | 7/4/2022 | 9/7/2026 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars. | |
| Modificada | Alta (7.5) | 0.80% | — | Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware | 7/4/2022 | 9/7/2026 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring. | |
| Modificada | Alta (8.8) | 1.00% | — | Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware | 7/4/2022 | 9/7/2026 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE. | |
| Modificada | Alta (7.5) | 14% | 💥 PoC | Rust-lang RegexFedoraproject FedoraDebian Linux | 8/3/2022 | 17/6/2026 | regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This… | |
| Modificada | Alta (7.8) | 0.42% | — | Trustedfirmware Trusted Firmware-m | 1/3/2022 | 17/6/2026 | Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations. | |
| Analizada | Media (5.5) | 0.83% | — | Virustotal Yara | 4/2/2022 | 17/6/2026 | A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service. | |
| Modificada | Media (6.3) | 1.4% | 💥 PoC | Rust-lang RustFedoraproject FedoraApple IpadosApple Iphone OS+3 | 20/1/2022 | 17/6/2026 | Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could… | |
| Modificada | Media (5.9) | 1.2% | — | Trustedfirmware Trusted Firmware-m | 13/1/2022 | 17/6/2026 | Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner. | |
| Modificada | Media (6.1) | 25% | 💥 Exploit | Beyondtrust Appliance Base Software | 5/1/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization. | |
| Modificada | Alta (7.5) | 1.6% | — | Rust-embed Project Rust-embed | 26/12/2021 | 17/6/2026 | An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode. | |
| Modificada | Alta (7.5) | 1.2% | — | Trustedfirmware Mbed TLSFedoraproject Fedora | 21/12/2021 | 17/6/2026 | In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application. | |
| Modificada | Crítica (9.8) | 2.6% | — | ARM Mbed TLSTrustedfirmware Mbed TLSDebian Linux | 20/12/2021 | 17/6/2026 | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Owasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+2 | 7/12/2021 | 17/6/2026 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for… | |
| Modificada | Alta (7.8) | 0.35% | — | Trustedfirmware Op-tee | 7/12/2021 | 17/6/2026 | An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure… | |
| Modificada | Alta (7.1) | 0.27% | — | Trustedfirmware Op-tee | 7/12/2021 | 17/6/2026 | The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral. | |
| Modificada | Alta (7.8) | 0.30% | — | Beyondtrust Privilege Management FOR Windows | 19/11/2021 | 17/6/2026 | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions. | |
| Modificada | Crítica (9.1) | 0.87% | — | Trustedfirmware Op-tee | 11/8/2021 | 17/6/2026 | In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information. | |
| Modificada | Media (5.9) | 0.98% | — | Disrustor Project Disrustor | 8/8/2021 | 17/6/2026 | An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references. | |
| Modificada | Crítica (9.1) | 2.6% | — | Rust-lang Rust | 7/8/2021 | 17/6/2026 | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. | |
| Modificada | Media (4.4) | 0.31% | — | Mongodb Rust Driver | 2/8/2021 | 17/6/2026 | Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such… |