Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.6% | — | Trusteddomain OpendmarcPypolicyd-spf Project Pypolicyd-spfFedoraproject Fedora | 27/4/2020 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. | |
| Modificada | Media (4.7) | 0.25% | — | ARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject FedoraDebian Linux | 15/4/2020 | 17/6/2026 | An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the… | |
| Modificada | Alta (7.5) | 1.0% | — | Beyondtrust Privilege Management FOR Windows AND MAC | 18/3/2020 | 17/6/2026 | BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a DefendpointService.exe crash. | |
| Modificada | Media (4.3) | 0.38% | — | Entrustdatacard Entelligence Security Provider | 18/3/2020 | 17/6/2026 | Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain. | |
| Modificada | Crítica (9.8) | 1.9% | — | Trustwave Mailmarshal | 19/2/2020 | 17/6/2026 | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection. | |
| Modificada | Crítica (9.8) | 3.2% | — | Apache Rust SGX SDK | 4/1/2020 | 17/6/2026 | Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same. | |
| Modificada | Alta (7.8) | 0.38% | — | Intel-sa-00125 Detection ToolIntel Sa-00086 Detection ToolIntel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version 1.2.7.0 or before; INTEL-SA-00125 Detection… | |
| Modificada | Media (6.7) | 0.37% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.35% | — | Intel Dynamic Application LoaderIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.35% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.31% | — | Intel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local… | |
| Modificada | Media (5.9) | 2.7% | — | Intel Platform Trust Technology FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0,… | |
| Modificada | Media (6.7) | 0.36% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local… | |
| Modificada | Alta (8.8) | 0.76% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access. | |
| Modificada | Media (4.4) | 0.35% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 18/12/2019 | 17/6/2026 | Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 1.5% | — | Virustotal YaraFedoraproject Fedora | 9/12/2019 | 17/6/2026 | In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Trustedsec Trevorc2 | 4/12/2019 | 17/6/2026 | TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "SITE_PATH_QUERY". | |
| Modificada | Media (5.5) | 0.39% | — | Trusted Boot Project Trusted BootRedhat Enterprise LinuxFedoraproject Fedora | 18/11/2019 | 17/6/2026 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability | |
| Modificada | Alta (7.5) | 1.3% | — | Rust-lang Rust | 30/9/2019 | 17/6/2026 | Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `Cargo.toml` is ignored in Rust 1.25.0 and prior. When Rust 1.25.0 and prior is used Cargo may download the wrong dependency, which could be… | |
| Modificada | Media (5.3) | 1.8% | — | ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora+1 | 26/9/2019 | 17/6/2026 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in… | |
| Modificada | Crítica (9.8) | 2.5% | — | Trusteddomain OpendmarcDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 17/9/2019 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message. | |
| Modificada | Media (6.1) | 0.97% | — | Trust Form Project Trust Form | 13/9/2019 | 17/6/2026 | The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter. | |
| Analizada | Crítica (9.8) | 4.9% | ⚠ Explotación activa | Trustedconnectivityalliance S@T Browser | 12/9/2019 | 17/6/2026 | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker. |