Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.33% | — | Linuxfoundation Wasmedge | 30/12/2025 | 17/6/2026 | WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue. | |
| Analizada | Alta (7.8) | 0.15% | — | Wasmi-labs Wasmi | 9/12/2025 | 17/6/2026 | Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 through 0.47.1, 0.50.0 through 0.51.2 and 1.0.0, Wasmi's linear memory implementation leads to a Use After Free vulnerability, triggered by a WebAssembly module under certain memory growth conditions.… | |
| Aplazada | Baja (1.8) | 0.11% | — | Bytecodealliance WasmtimeAI | 12/11/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not… | |
| Analizada | Baja (2.1) | 0.43% | — | Bytecodealliance Wasmtime | 24/10/2025 | 1/10/2026 | Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert… | |
| Analizada | Baja (1) | 0.19% | — | Bytecodealliance Wasmtime | 7/10/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development of 37.0.0 and all prior versions of Wasmtime are unaffected. If `anyref` or… | |
| Aplazada | Alta (8.6) | 0.37% | — | DuckdbAIDuckdb Node-apiAIDuckdb Node-bindingsAIDuckdb-wasmAI | 9/9/2025 | 17/6/2026 | DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin… | |
| Analizada | Alta (7.5) | 0.38% | — | Cosmwasm Serde-json-wasm | 27/7/2025 | 17/6/2026 | The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data. | |
| Analizada | Media (5.3) | 0.43% | — | Cosmwasm-std | 27/7/2025 | 17/6/2026 | The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations. | |
| Analizada | Baja (3.5) | 0.33% | — | Bytecodealliance Wasmtime | 18/7/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest inducing a panic in the host (embedder). The specific bug is triggered by calling `path_open` after calling `fd_renumber` with… | |
| Analizada | Baja (1.9) | 0.23% | — | Wasm3 Project Wasm3 | 19/6/2025 | 17/6/2026 | A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.5) | 0.78% | — | Cosmwasm | 18/3/2025 | 17/6/2026 | An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain. | |
| Analizada | Alta (8.4) | 0.22% | — | Wasm3 Project Wasm3 | 8/11/2024 | 17/6/2026 | wasm3 139076a contains a Use-After-Free in ForEachModule. | |
| Analizada | Alta (8.4) | 0.26% | — | Wasm3 Project Wasm3 | 8/11/2024 | 17/6/2026 | wasm3 139076a contains memory leaks in Read_utf8. | |
| Analizada | Alta (8.4) | 0.24% | — | Wasm3 Project Wasm3 | 8/11/2024 | 17/6/2026 | wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution. | |
| Analizada | Alta (7.5) | 0.46% | — | Wasm3 Project Wasm3 | 8/11/2024 | 17/6/2026 | wasm3 139076a is vulnerable to Denial of Service (DoS). | |
| Analizada | Baja (2.3) | 0.84% | — | Bytecodealliance Wasmtime | 5/11/2024 | 17/6/2026 | Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, such as "COM¹",… | |
| Analizada | Baja (2.9) | 0.15% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption could, following an… | |
| Analizada | Media (5.5) | 0.24% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was compiled with Rust 1.80 or prior. The runtime crash is a… | |
| Aplazada | Baja (2.9) | 0.20% | — | WasmerAI | 19/6/2024 | 17/6/2026 | Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink pointing outside, WASI programs can traverse the symlink and access host filesystem if the caller sets both `oflags::creat` and `rights::fd_write`. Programs can also crash the runtime by creating a… | |
| Analizada | Alta (7.5) | 0.52% | — | Wasm3 Project Wasm3 | 6/5/2024 | 17/6/2026 | wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c. | |
| Analizada | Alta (7.5) | 0.63% | — | Wasm3 Project Wasm3 | 6/5/2024 | 17/6/2026 | wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c. | |
| Analizada | Crítica (9.8) | 0.71% | — | Wasm3 Project Wasm3 | 6/5/2024 | 17/6/2026 | wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c. | |
| Analizada | Media (5.5) | 0.32% | — | Bytecodealliance Wasmtime | 4/4/2024 | 17/6/2026 | wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched… | |
| Analizada | Crítica (9.8) | 0.80% | — | Wasmi-labs Wasmi | 21/3/2024 | 17/6/2026 | Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will arise if the host calls or resumes a Wasm function with more parameters than the default limit (128), as it will surpass the stack value. This… | |
| Modificada | Alta (8.6) | 0.60% | — | Wasmer | 22/12/2023 | 17/6/2026 | Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host filesystem. This vulnerability has been… |