Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.67%—Bytecodealliance Wasmtime15/9/202317/6/2026
Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` instruction on x86_64 platforms when the shift amount is a constant value that is larger than 32. Only x86_64 is affected so all other targets…
ModificadaAlta (8.8)0.45%—Bytecodealliance Wasmtime27/4/202317/6/2026
Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation of managing per-instance state, such as tables and memories, contains LLVM-level undefined behavior. This undefined behavior was found to cause runtime-level issues when compiled with LLVM 16 which…
ModificadaMedia (4.3)0.62%—Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime8/3/202317/6/2026
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than…
ModificadaCrítica (9.9)1.3%—Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime8/3/202317/6/2026
wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective address. This bug means that, with default…
ModificadaAlta (8.1)0.82%—Dash7-alliance Dash7 Alliance Protcol1/3/202317/6/2026
The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write prior to implementation version 0.5.0. If the protocol has been compiled using default settings, this will only grant the attacker access to allocated but unused memory. However, if it was configured…
ModificadaAlta (7.5)0.53%—Forged Alliance Forever Project Forged Alliance Forever6/1/202317/6/2026
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named…
ModificadaAlta (8.8)1.1%—Telosalliance Omnia MPX Node Firmware2/12/202217/6/2026
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.
ModificadaCrítica (9.8)6.0%—Telosalliance Omnia MPX Node Firmware2/12/202217/6/2026
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
ModificadaAlta (7.5)0.70%—Telosalliance Omnia MPX Node Firmware29/11/202217/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.
ModificadaCrítica (9.8)0.34%—Bytecodealliance Wasmtime10/11/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementation where the definition of the `wasmtime_trap_code` does not match its declared signature in the `wasmtime/trap.h` header file. This discrepancy causes the function implementation to perform a…
ModificadaAlta (8.6)0.71%—Bytecodealliance Wasmtime10/11/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance.…
ModificadaAlta (7.4)0.63%—Bytecodealliance Wasmtime10/11/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator when the allocator is configured to give WebAssembly instances a maximum of zero pages of memory. In this configuration, the virtual memory mapping for WebAssembly…
ModificadaCrítica (9.8)13%💥 ExploitTelosalliance Omnia MPX Node Firmware2/9/202217/6/2026
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be…
ModificadaAlta (7.5)0.92%—Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime22/7/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 targets where constant divisors can result in incorrect division results at runtime. This affects Wasmtime prior to version 0.38.2 and Cranelift prior to 0.85.2. This issue only affects the AArch64…
ModificadaAlta (8.8)1.3%—Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime21/7/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. There is a bug in the Wasmtime's code generator, Cranelift, where functions using reference types may be incorrectly missing metadata required for runtime garbage collection. This means that if a GC happens at runtime then the GC pass will mistakenly think these…
ModificadaMedia (5.6)1.8%—Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime28/6/202217/6/2026
Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal for WebAssembly on x86_64 contained two distinct bugs in the instruction lowerings implemented in Cranelift. The aarch64 implementation of the simd proposal is not affected. The bugs were presented in…
ModificadaCrítica (9.8)1.2%—Bytecodealliance Wasmtime31/3/202217/6/2026
Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are not explicitly enabling epoch interruption (it is disabled by default) then you are not…
ModificadaAlta (8.1)0.77%💥 PoCBytecodealliance Wasmtime16/2/202217/6/2026
Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a failure to instantiate an instance for a module that defines an `externref` global will result in an invalid drop of a `VMExternRef` via an…
ModificadaCrítica (9.8)4.3%—Telosalliance Z/ip ONE Firmware24/1/202217/6/2026
A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password for remote configuration of the device…
ModificadaAlta (8.1)1.6%—Bytecodealliance Lucet30/11/202117/6/2026
Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all versions published to crates.io that allows a use-after-free in an Instance object that could result in memory corruption, data race, or other related issues. This bug was introduced early in the…
ModificadaMedia (6.3)0.30%—Bytecodealliance WasmtimeFedoraproject Fedora17/9/202117/6/2026
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is affected by a memory unsoundness vulnerability. There was an invalid free and out-of-bounds read and write bug when running Wasm that uses `externref`s in Wasmtime. To trigger this bug, Wasmtime…
ModificadaMedia (6.3)0.36%—Bytecodealliance WasmtimeFedoraproject Fedora17/9/202117/6/2026
Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and which are `unsafe`, guaranteeing that if consumers never use `unsafe` then it should not be possible…
ModificadaMedia (6.3)0.31%—Bytecodealliance WasmtimeFedoraproject Fedora17/9/202117/6/2026
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 there was a use-after-free bug when passing `externref`s from the host to guest Wasm content. To trigger the bug, you have to explicitly pass multiple `externref`s from the host to a Wasm instance at…
ModificadaAlta (8.8)0.46%—Bytecodealliance Cranelift-codegen24/5/202117/6/2026
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a scenario that could result in a potential sandbox escape in a Wasm program. This…
ModificadaAlta (7.5)0.93%—Business Alliance Financial Circle Project Business Alliance Financial Circle31/12/201917/6/2026
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's identity.