Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.13% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time… | |
| Analizada | Baja (3.3) | 0.15% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. Version 4.11.0 contains a patch. No known… | |
| Analizada | Media (5.5) | 0.15% | — | Trustedfirmware Op-tee | 6/7/2026 | 7/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a… | |
| Analizada | Alta (8.5) | 0.53% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/7/2026 | 7/7/2026 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources… | |
| Analizada | Alta (8.7) | 0.65% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/7/2026 | 7/7/2026 | BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance… | |
| Analizada | Crítica (9.2) | 0.75% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/7/2026 | 7/7/2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated… | |
| Analizada | Crítica (9.2) | 0.46% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/7/2026 | 7/7/2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts… | |
| Aplazada | Alta (7.2) | 0.33% | — | RustdeskAI | 28/6/2026 | 18/7/2026 | RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and… | |
| Aplazada | Media (4.3) | 0.27% | — | RustfsAI | 26/6/2026 | 27/6/2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls validate_admin_request to enforce admin-action… | |
| Aplazada | Alta (7.7) | 0.34% | — | RustfsAI | 26/6/2026 | 29/6/2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP write/list handlers (and the entire HTTP S3… | |
| Aplazada | Alta (8.2) | 0.30% | — | RustfsAI | 26/6/2026 | 27/6/2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request credentials exist, but does not verify… | |
| Aplazada | Alta (8.6) | 0.41% | — | RustfsAI | 26/6/2026 | 29/6/2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users' buckets, completely breaking multi-tenant… | |
| Analizada | Alta (8.7) | 0.73% | — | Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+1 | 9/6/2026 | 24/7/2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by… | |
| Analizada | Media (5.5) | 0.17% | — | Trustedfirmware Op-tee | 3/6/2026 | 22/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability exists in OP-TEE OS when processing an FFA_MEM_SHARE request from the… | |
| Analizada | Media (4.7) | 0.09% | — | Trustedfirmware Op-tee | 3/6/2026 | 22/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't verified to be a point on the correct curve. By passing approximately… | |
| Analizada | Alta (7.8) | 0.21% | — | Trustedfirmware Op-tee | 3/6/2026 | 21/7/2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A within OP-TEE… | |
| Aplazada | Crítica (9.3) | 0.35% | — | RustfsAI | 29/5/2026 | 21/7/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts… | |
| Aplazada | Media (6.9) | 0.54% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console listener and returns JSON containing license information such as the… | |
| Aplazada | Media (6) | 0.15% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and also sets Access-Control-Allow-Credentials: true and… | |
| Aplazada | Alta (8.8) | 0.54% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the… | |
| Aplazada | Alta (7.1) | 0.35% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources. The implementation validates GetObject permission on the source… | |
| Aplazada | Alta (8.7) | 0.41% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" license tokens. Because the key is embedded in every published source… | |
| Aplazada | Media (5.3) | 0.24% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT claims are printed in plaintext to the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in crates/ecstore/src/rpc/http_auth.rs, falls back to the public,… | |
| Analizada | Media (6.5) | 0.41% | — | Rust-lang Cargo | 25/5/2026 | 23/7/2026 | Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not… |