Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.54%—Rust-lang Rust20/8/201817/6/2026
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function that can result in Arbitrary code execution, but no proof-of-concept…
ModificadaAlta (7.1)0.52%💥 PoCTrustedcomputinggroup Trusted Platform Module17/8/201817/6/2026
An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It…
ModificadaAlta (7.8)1.8%—Rust-lang Rust9/7/201817/6/2026
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user. This attack appear to be exploitable via using the --plugin flag without the --plugin-path flag. This…
ModificadaMedia (6.1)0.66%—Entrustdatacard Syntera Customization Suite5/7/201817/6/2026
Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
ModificadaAlta (7.5)1.1%—Trustzen Project Trustzen5/7/201817/6/2026
The mintToken function of a smart contract implementation for Trust Zen Token (ZEN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.8)1.3%—Virustotal Yara15/6/201817/6/2026
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c.
ModificadaAlta (7.8)1.3%—Virustotal Yara15/6/201817/6/2026
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.
ModificadaMedia (4.9)0.54%—LibtomcryptTrustedfirmware Op-tee15/6/201817/6/2026
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
ModificadaAlta (7.8)0.86%—Virustotal13/6/201817/6/2026
An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.
ModificadaAlta (7.8)0.33%—Londontrustmedia Private Internet Access17/4/201817/6/2026
A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vulnerability is due to insufficient implementation of access controls. The "Changelog" and "Help" options available from…
ModificadaAlta (7.5)2.1%—ARM Mbed TLSTrustedfirmware Mbed TLSDebian Linux10/4/201817/6/2026
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
ModificadaAlta (7.5)2.1%—ARM Mbed TLSTrustedfirmware Mbed TLSDebian Linux10/4/201817/6/2026
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
ModificadaCrítica (9.8)1.5%—Rust-base64 Project Rust-base642/1/201817/6/2026
rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions
ModificadaCrítica (9.8)14%💥 ExploitTrustwave Secure WEB Gateway31/12/201717/6/2026
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
ModificadaAlta (7.8)0.61%—Intel Trusted Execution Engine Firmware21/11/201717/6/2026
Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unauthorized process to access privileged content via unspecified vector.
ModificadaAlta (7.8)0.65%—Intel Trusted Execution Engine Firmware21/11/201717/6/2026
Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.
ModificadaAlta (7.8)0.41%—Trusted Boot Project Trusted Boot16/11/201717/6/2026
Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers.
ModificadaAlta (7.8)1.3%—Beyondtrust Remote Support26/10/201717/6/2026
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
ModificadaAlta (7.5)1.8%—Londontrustmedia Private Internet Access26/10/201717/6/2026
The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to cause a denial of service (application crash) via a large VPN server-list file.
ModificadaMedia (5.9)9.8%💥 PoCInfineon Trusted Platform FirmwareInfineon RSA Library16/10/201717/6/2026
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection…
ModificadaMedia (4.4)0.32%—Juniper Trusted Platform Module Firmware13/10/201717/6/2026
Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX300 Series to encrypt sensitive configuration data. While other…
AnalizadaAlta (7)0.79%—Trustedfirmware Trusted Firmware-a20/9/201717/6/2026
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.
ModificadaAlta (8.1)1.5%—ARM Mbed TLSTrustedfirmware Mbed TLS30/8/201717/6/2026
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
ModificadaMedia (5.5)0.67%—Virustotal Yara17/7/201717/6/2026
Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.
ModificadaMedia (5.9)0.50%—Fountaintrust Fountain Trust Mobile Banking16/6/201717/6/2026
The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id891343006 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades