Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is… | |
| Analizada | Media (5.5) | 0.19% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4. | |
| Aplazada | Baja (1.8) | 0.11% | — | Bytecodealliance WasmtimeAI | 12/11/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not… | |
| Analizada | Media (6.5) | 0.31% | — | Chipsalliance Rocketchip | 10/11/2025 | 17/6/2026 | A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP… | |
| Analizada | Baja (2.1) | 0.43% | — | Bytecodealliance Wasmtime | 24/10/2025 | 1/10/2026 | Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert… | |
| Analizada | Baja (1) | 0.19% | — | Bytecodealliance Wasmtime | 7/10/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development of 37.0.0 and all prior versions of Wasmtime are unaffected. If `anyref` or… | |
| Analizada | Alta (7.5) | 0.64% | — | Chipsalliance Rocket-chip | 30/9/2025 | 17/6/2026 | An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between exception handling and MRET return mechanisms in the CSR logic when an exception is… | |
| Analizada | Baja (2.1) | 0.37% | — | Bytecodealliance Webassembly Micro Runtime | 16/9/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address pointer) is greater… | |
| Analizada | Media (6.9) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 29/7/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP… | |
| Analizada | Baja (3.5) | 0.33% | — | Bytecodealliance Wasmtime | 18/7/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest inducing a panic in the host (embedder). The specific bug is triggered by calling `path_open` after calling `fd_renumber` with… | |
| Analizada | Alta (7) | 0.28% | — | Bytecodealliance Webassembly Micro Runtime | 15/5/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following… | |
| Aplazada | Alta (7.5) | 0.55% | — | Connectivity Standards Alliance MatterAI | 18/12/2024 | 17/6/2026 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion). | |
| Aplazada | Media (6.9) | 0.67% | — | Open Design Alliance CDE Inweb SDKAIOpen Design Alliance CDE ServerAI | 12/12/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default settings allows unauthorized users to visit prometheus metrics page. This can allow attackers to understand more things about the target… | |
| Aplazada | Alta (8.8) | 2.5% | 💥 PoC | Wi-fi Alliance Wi-fi Test SuiteAIArcadyan Fmimg51ax000jAI | 11/11/2024 | 17/6/2026 | Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On… | |
| Analizada | Alta (7.5) | 0.51% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | |
| Analizada | Alta (7.8) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | |
| Analizada | Baja (2.3) | 0.84% | — | Bytecodealliance Wasmtime | 5/11/2024 | 17/6/2026 | Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, such as "COM¹",… | |
| Analizada | Baja (2.9) | 0.15% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption could, following an… | |
| Analizada | Media (5.5) | 0.24% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was compiled with Rust 1.80 or prior. The runtime crash is a… | |
| Analizada | Baja (3.8) | 0.43% | — | Dwalliance Easyevent | 7/5/2024 | 17/6/2026 | The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Alta (7.5) | 0.76% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |
| Analizada | Media (6.2) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c. | |
| Analizada | Media (5.5) | 0.32% | — | Bytecodealliance Wasmtime | 4/4/2024 | 17/6/2026 | wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched… | |
| Modificada | Media (5.5) | 0.32% | — | Bytecodealliance Webassembly Micro Runtime | 31/12/2023 | 17/6/2026 | Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled. | |
| Modificada | Alta (7.5) | 1.0% | — | Bytecodealliance Webassembly Micro Runtime | 22/11/2023 | 9/7/2026 | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c. |