Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.14% | — | Beyondtrust Privilege Management FOR WindowsAI | 2/2/2026 | 17/6/2026 | A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass the product’s anti-tamper protections, which could allow access to protected application components… | |
| Analizada | Media (5.3) | 0.29% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for example, a fragmented/partial ClientHello split across TCP writes),… | |
| Analizada | Alta (7.1) | 0.26% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The… | |
| Aplazada | Media (5.3) | 0.34% | — | Rustcrypto Ml-dsaAI | 28/1/2026 | 17/6/2026 | The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices.… | |
| Aplazada | Media (5.3) | 0.24% | — | Rustaurius Ultimate ReviewsAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16. | |
| Analizada | Alta (7.5) | 0.40% | — | Trustwallet Trust Wallet Core | 20/1/2026 | 17/6/2026 | A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Baja (2.9) | 0.53% | — | Rustfs | 16/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid… | |
| Aplazada | Crítica (9.3) | 1.2% | — | Entrust Instant Financial IssuanceAI | 15/1/2026 | 17/6/2026 | Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with… | |
| Analizada | Alta (8.9) | 0.57% | — | Rustcrypto Cmov | 15/1/2026 | 17/6/2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (portable version).… | |
| Aplazada | Media (6.4) | 0.16% | — | Rustcrypto SignaturesAI | 10/1/2026 | 17/6/2026 | RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel was discovered in the Decompose algorithm which is used during ML-DSA signing to generate hints for the signature. This issue has been… | |
| Analizada | Alta (7.5) | 0.31% | — | Rustcrypto SM2 Elliptic Curve | 10/1/2026 | 17/6/2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2… | |
| Analizada | Alta (7.5) | 0.44% | — | Rustcrypto SM2 Elliptic Curve | 10/1/2026 | 17/6/2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2 PKE… | |
| Analizada | Alta (8.7) | 0.27% | — | Rustcrypto SM2 Elliptic Curve | 10/1/2026 | 17/6/2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical vulnerability exists in the SM2 Public Key… | |
| Analizada | Media (5.7) | 0.42% | — | Rustfs | 8/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables… | |
| Analizada | Media (5.7) | 0.43% | — | Rustfs | 8/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to perform import operations. Since importing IAM data performs… | |
| Analizada | Baja (2.7) | 0.44% | — | Rustcrypto RSA | 8/1/2026 | 17/6/2026 | The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue. | |
| Analizada | Media (5.5) | 0.34% | — | Rustfs | 7/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler thread and enabling remote denial of service of the metrics endpoint. This… | |
| Analizada | Alta (8.8) | 7.3% | — | Rustfs | 7/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79. | |
| Aplazada | Alta (8.6) | 0.27% | — | Rustaurius Five Star Restaurant ReservationsAI | 5/1/2026 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4. | |
| Analizada | Crítica (9.8) | 32% | — | Rustfs | 30/12/2025 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for… | |
| Aplazada | Media (5.4) | 0.12% | — | Rustaurius Five Star Restaurant ReservationsAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8. | |
| Aplazada | Media (5.3) | 0.27% | — | Trustindex Widgets FOR Social Photo FeedAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widgets for Social Photo Feed: from n/a through <= 1.8. | |
| Aplazada | Media (6.4) | 0.23% | — | Trustindex Widgets FOR Google ReviewsAI | 11/12/2025 | 30/9/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trustindex` shortcode in all versions up to, and including, 13.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.95% | — | Entrust Instant Financial IssuanceAI | 9/12/2025 | 17/6/2026 | Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary… | |
| Aplazada | Media (4.3) | 0.12% | — | Rustaurius Ultimate FAQAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3. |