Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.18% | — | ARM Mbed TLSTrustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). | |
| Analizada | Alta (7.5) | 0.53% | — | Trustedfirmware Mbed TLS | 1/4/2026 | 17/6/2026 | Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function | |
| Analizada | Crítica (9.8) | 0.60% | — | Trustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. | |
| Analizada | Media (6.5) | 0.22% | — | Trustedfirmware Mbed TLS | 1/4/2026 | 17/6/2026 | Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. | |
| Aplazada | Media (6.5) | 0.38% | — | Activitypub-federation-rustAIJoin-lemmy LemmyAI | 27/3/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF… | |
| Aplazada | Media (6.5) | 0.21% | — | Rustaurius Five Star Restaurant ReservationsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Trusteer Rapport | 10/3/2026 | 17/6/2026 | IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute… | |
| Modificada | Alta (8.2) | 0.34% | — | Rustdesk | 5/3/2026 | 22/6/2026 | Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with… | |
| Analizada | Crítica (9.3) | 0.58% | — | Rustdesk | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files… | |
| Modificada | Media (6.9) | 0.51% | — | Rustdesk Server | 5/3/2026 | 19/7/2026 | Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password… | |
| Analizada | Alta (8.7) | 0.33% | — | Rustdesk | 5/3/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON… | |
| Analizada | Crítica (9.3) | 0.35% | — | Rustdesk | 5/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutter_ffi.Rs and… | |
| Modificada | Alta (8.3) | 0.31% | — | Rustdesk | 5/3/2026 | 22/6/2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files… | |
| Modificada | Media (5.7) | 0.34% | — | Rustdesk | 5/3/2026 | 22/6/2026 | Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication… | |
| Analizada | Alta (8.2) | 0.16% | — | Rustdesk | 5/3/2026 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows… | |
| Modificada | Media (4.8) | 0.47% | — | Rustdesk | 5/3/2026 | 22/6/2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program… | |
| Analizada | Alta (8.7) | 0.33% | — | Rustdesk Server | 5/3/2026 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routines Config… | |
| Analizada | Alta (8.7) | 0.34% | — | Rustdesk | 5/3/2026 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files… | |
| Analizada | Media (5.4) | 0.37% | — | Rustfs | 25/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an attacker can steal… | |
| Analizada | Crítica (9.1) | 0.41% | — | Rustfs | 25/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enables unauthorized file… | |
| Aplazada | Media (5.5) | 0.33% | — | Rustdesk ClientAI | 20/2/2026 | 17/6/2026 | RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Aplazada | Crítica (9.3) | 3.0% | — | RustflyAI | 19/2/2026 | 17/6/2026 | RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including… | |
| Analizada | Crítica (9.9) | 91% | ⚠ Explotación activa | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/2/2026 | 17/6/2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site… | |
| Analizada | Media (6.9) | 0.28% | — | Rustfs | 3/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) to application logs at INFO level. This results in credentials being recorded in plaintext in log output, which may be accessible to… | |
| Analizada | Alta (7.7) | 0.24% | — | Rustfs | 3/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable client can spoof aws:SourceIp and satisfy IP-allowlist policies.… |