Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.31% | — | Wp-formassemblyAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10. | |
| Modificada | Media (5.5) | 0.32% | — | Bytecodealliance Webassembly Micro Runtime | 31/12/2023 | 17/6/2026 | Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled. | |
| Modificada | Alta (7.5) | 1.0% | — | Bytecodealliance Webassembly Micro Runtime | 22/11/2023 | 9/7/2026 | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c. | |
| Modificada | Media (5.5) | 0.21% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault. | |
| Modificada | Media (5.5) | 0.27% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault. | |
| Modificada | Media (6.5) | 0.62% | — | Webassembly Binaryen | 22/8/2023 | 17/6/2026 | Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt. | |
| Modificada | Media (6.5) | 0.61% | — | Webassembly Binaryen | 22/8/2023 | 17/6/2026 | A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as. | |
| Modificada | Media (6.1) | 0.43% | — | Assemblysoftware Trialworks | 24/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the asset src parameter. | |
| Modificada | Media (5.5) | 0.28% | — | Webassembly Binary Toolkit | 23/5/2023 | 17/6/2026 | WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote ("). | |
| Modificada | Alta (7.5) | 0.83% | — | Webassembly Binary Toolkit | 23/5/2023 | 17/6/2026 | An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary. | |
| Modificada | Media (5.5) | 0.28% | — | W3 Webassembly | 3/5/2023 | 17/6/2026 | An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop. | |
| Modificada | Media (5.5) | 0.28% | — | Webassembly Wabt | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | |
| Modificada | Alta (7.8) | 0.32% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator. | |
| Modificada | Media (5.5) | 0.29% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType. | |
| Modificada | Media (5.5) | 0.31% | — | Webassembly | 10/3/2023 | 17/6/2026 | WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size. | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Media (5.5) | 0.27% | — | Webassembly Wabt | 28/10/2022 | 17/6/2026 | wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. | |
| Modificada | Alta (7.1) | 0.31% | — | Webassembly Wabt | 28/10/2022 | 17/6/2026 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount. | |
| Modificada | Alta (7.8) | 0.33% | — | Webassembly Wasm | 28/10/2022 | 17/6/2026 | wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h. | |
| Modificada | Alta (7.1) | 0.31% | — | Webassembly Wabt | 28/10/2022 | 17/6/2026 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount. | |
| Modificada | Alta (7.8) | 0.38% | — | Autodesk Subassembly Composer | 14/10/2022 | 17/6/2026 | A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.55% | — | Autodesk Subassembly Composer | 14/10/2022 | 17/6/2026 | A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.41% | — | Autodesk Subassembly Composer | 14/10/2022 | 17/6/2026 | A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.41% | — | Autodesk Subassembly Composer | 3/10/2022 | 17/6/2026 | A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Media (5.5) | 0.18% | — | Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+21 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using… |