Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | RustfsAI | 12/8/2026 | 9/9/2026 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to disclose known historical object content.… | |
| Analizada | Media (4.6) | 0.30% | — | Intel Trust Domain Extensions Guest | 11/8/2026 | 18/8/2026 | Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local… | |
| Analizada | Media (4.6) | 0.15% | — | Intel Trust Domain Extensions Guest | 11/8/2026 | 18/8/2026 | Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local… | |
| Pendiente de análisis | Media (5.7) | 0.07% | — | Intel Trust Domain ExtensionsAI | 11/8/2026 | 29/9/2026 | Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially… | |
| Pendiente de análisis | Alta (8) | 0.42% | — | Trustyai ServiceAI | 10/8/2026 | 21/9/2026 | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the… | |
| Pendiente de análisis | Alta (8.1) | 0.60% | — | Trustyai-service-operatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code… | |
| Aplazada | Alta (7.1) | 0.46% | — | Rust-lang Tar-rsAI | 10/8/2026 | 24/9/2026 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Rust-iot-platformAI | 5/8/2026 | 26/8/2026 | rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Rust-iot-platformAI | 5/8/2026 | 26/8/2026 | rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. ) satisfies the guard, granting… | |
| Aplazada | Media (6) | 0.16% | — | Trusted MEMAI | 3/8/2026 | 28/8/2026 | In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533. | |
| Pendiente de análisis | Alta (8.7) | 0.75% | — | Amazon Smithy RSAIAmazon AWS SDK RustAI | 21/7/2026 | 22/7/2026 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation… | |
| Analizada | Media (4.4) | 0.19% | — | Msiemens Rust Onenote File Parser | 20/7/2026 | 18/8/2026 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed… | |
| Pendiente de análisis | Media (5.3) | 0.42% | — | Opentelemetry RustAI | 17/7/2026 | 23/7/2026 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap… | |
| Analizada | Baja (2) | 0.16% | — | Rustcrypto Cmov | 17/7/2026 | 18/8/2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. From 0.1.1 until 0.5.4, the aarch64 implementations of Cmov and CmovEq in cmov/src/backends/aarch64.rs assume high bits are zero-extended when… | |
| Aplazada | Crítica (9) | 0.49% | — | Rustfs ConsoleAI | 15/7/2026 | 16/7/2026 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the… | |
| Aplazada | Alta (8.7) | 0.50% | — | RustdeskAI | 10/7/2026 | 11/8/2026 | RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this… | |
| Aplazada | Alta (8.4) | 0.13% | — | Qualcomm Fabrickeymaster TrustletAI | 10/7/2026 | 11/7/2026 | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |
| Aplazada | Media (5.3) | 0.46% | — | Token OF Trust AGE Verification Identity VerificationAI | 9/7/2026 | 9/7/2026 | The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress 'init' hook, which fires for all requests, including those from… | |
| Pendiente de análisis | Media (6.3) | 0.28% | — | Trustyai-service-operatorAITrustyai GorchAI | 8/7/2026 | 31/8/2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… | |
| Analizada | Baja (3.8) | 0.19% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM implementation cause the authentication tag to be… | |
| Analizada | Media (5.5) | 0.18% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey… | |
| Analizada | Baja (3.8) | 0.15% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function… | |
| Analizada | Baja (3.3) | 0.14% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses… | |
| Analizada | Baja (3.3) | 0.13% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time `memcmp()`… |