Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Virustotal YaraAI | 22/9/2026 | 25/9/2026 | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can… | |
| Pendiente de análisis | Media (5.9) | 0.20% | — | Rustls WebpkiAI | 18/9/2026 | 22/9/2026 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked… | |
| Pendiente de análisis | Baja (2.1) | 0.18% | — | Rustls WebpkiAI | 18/9/2026 | 22/9/2026 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for… | |
| Pendiente de análisis | Baja (2.1) | 0.18% | — | Rustls WebpkiAI | 18/9/2026 | 22/9/2026 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on otherwise properly issued certificates, the… | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | Rustls WebpkiAI | 18/9/2026 | 22/9/2026 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty… | |
| Pendiente de análisis | Media (6.8) | 0.50% | — | Rust RmcpAI | 16/9/2026 | 23/9/2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from… | |
| Aplazada | Alta (8.2) | 0.20% | — | Rust RmcpAI | 16/9/2026 | 30/9/2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without… | |
| Aplazada | Alta (8.7) | 0.56% | — | RustypasteAI | 13/9/2026 | 23/9/2026 | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations. | |
| Analizada | Media (6.1) | 0.48% | — | Mongodb Rust Driver | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Aplazada | Alta (7.1) | 0.25% | — | TrustedsiteAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | |
| Aplazada | Alta (8.7) | 0.47% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without… | |
| Analizada | Alta (7.1) | 0.36% | — | Mongodb Rust Driver | 27/8/2026 | 29/9/2026 | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same… | |
| Aplazada | Alta (8.7) | 0.77% | — | RustdeskAI | 26/8/2026 | 23/9/2026 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823… | |
| Aplazada | Media (6.9) | 0.39% | — | RustdeskAI | 26/8/2026 | 23/9/2026 | RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard… | |
| Aplazada | Alta (7) | 0.17% | — | ARM Trusted Firmware-mAIInfineon Psoc64AIRaspberrypi Rp2350AI | 26/8/2026 | 9/9/2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | |
| Aplazada | Alta (8.5) | 0.43% | — | RustdeskAIFreerdpAI | 24/8/2026 | 23/9/2026 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a… | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Beyondtrust Endpoint Privilege ManagementAI | 17/8/2026 | 18/8/2026 | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds. | |
| Aplazada | Media (5.3) | 0.42% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path applies… | |
| Aplazada | Alta (8.1) | 0.41% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using each other's semantics because… | |
| Aplazada | Media (6.1) | 0.39% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or… | |
| Aplazada | Media (5.4) | 0.37% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated FTPS users denied s3:CreateBucket to… | |
| Aplazada | Alta (8.1) | 0.43% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated… | |
| Aplazada | Alta (7.5) | 0.46% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa, causing… | |
| Aplazada | Alta (8.8) | 0.52% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and prepare_service_account_auth sets is_owner for the… |