Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.31%—Wp-formassemblyAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10.
ModificadaMedia (5.5)0.32%—Bytecodealliance Webassembly Micro Runtime31/12/202317/6/2026
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
ModificadaAlta (7.5)1.0%—Bytecodealliance Webassembly Micro Runtime22/11/20239/7/2026
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
ModificadaMedia (5.5)0.21%—Webassembly Binary Toolkit23/10/202317/6/2026
WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.
ModificadaMedia (5.5)0.27%—Webassembly Binary Toolkit23/10/202317/6/2026
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
ModificadaMedia (6.5)0.62%—Webassembly Binaryen22/8/202317/6/2026
Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.
ModificadaMedia (6.5)0.61%—Webassembly Binaryen22/8/202317/6/2026
A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
ModificadaMedia (6.1)0.43%—Assemblysoftware Trialworks24/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the asset src parameter.
ModificadaMedia (5.5)0.28%—Webassembly Binary Toolkit23/5/202317/6/2026
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
ModificadaAlta (7.5)0.83%—Webassembly Binary Toolkit23/5/202317/6/2026
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
ModificadaMedia (5.5)0.28%—W3 Webassembly3/5/202317/6/2026
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
ModificadaMedia (5.5)0.28%—Webassembly Wabt10/3/202317/6/2026
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
ModificadaAlta (7.8)0.32%—Webassembly10/3/202317/6/2026
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
ModificadaMedia (5.5)0.29%—Webassembly10/3/202317/6/2026
WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.
ModificadaMedia (5.5)0.31%—Webassembly10/3/202317/6/2026
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
ModificadaAlta (7.8)0.16%—Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+2026/12/202217/6/2026
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
ModificadaMedia (5.5)0.27%—Webassembly Wabt28/10/202217/6/2026
wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
ModificadaAlta (7.1)0.31%—Webassembly Wabt28/10/202217/6/2026
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
ModificadaAlta (7.8)0.33%—Webassembly Wasm28/10/202217/6/2026
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
ModificadaAlta (7.1)0.31%—Webassembly Wabt28/10/202217/6/2026
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
ModificadaAlta (7.8)0.38%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.55%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.41%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.41%—Autodesk Subassembly Composer3/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaMedia (5.5)0.18%—Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+2126/7/202217/6/2026
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using…