Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.3) | 0.41% | — | Matrix-rust-sdk | 9/12/2025 | 17/6/2026 | matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join… | |
| Modificada | Media (4.6) | 0.26% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password. | |
| Modificada | Crítica (9.1) | 0.46% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB… | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components. | |
| Modificada | Media (4.1) | 0.19% | — | Entrust Nshield Connect XC High FirmwareEntrust Nshield Connect XC MID FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Hsmi Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted). | |
| Modificada | Baja (3.9) | 0.18% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection). | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader. | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06. | |
| Modificada | Baja (3.2) | 0.24% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board. | |
| Modificada | Crítica (9.8) | 0.67% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04. | |
| Modificada | Media (6.8) | 0.32% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the… | |
| Modificada | Crítica (9.8) | 0.90% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving… | |
| Aplazada | Baja (1) | 0.12% | — | Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI | 23/11/2025 | 17/6/2026 | The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in… | |
| Aplazada | Alta (8.6) | 0.18% | 💥 PoC | ARM Trusted Firmware-aAI | 23/11/2025 | 17/6/2026 | The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC. | |
| Aplazada | Media (5) | 0.25% | — | TrustyaiAIRedhat Openshift AIAI | 28/10/2025 | 19/7/2026 | A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any namespace on the cluster. TrustyAI is creating a role `trustyai-service-operator-lmeval-user-role` and a CRB… | |
| Aplazada | Media (4.3) | 0.20% | — | Rustaurius Front END UsersAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users.This issue affects Front End Users: from n/a through <= 3.2.33. | |
| Aplazada | Alta (7.8) | 0.32% | — | Truffle Security CO Trustflesecurity CO TrufflehogAI | 20/10/2025 | 17/6/2026 | An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.18% | — | Mongodb Rust Driver | 13/10/2025 | 17/6/2026 | When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5 | |
| Aplazada | Alta (7.5) | 0.36% | — | Cel-rustAI | 10/10/2025 | 17/6/2026 | cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can cause the parser to panic, terminating the process. When the crate is used to evaluate untrusted expressions (e.g., user-supplied input over an… | |
| Aplazada | Alta (8.7) | 0.30% | — | Beyondtrust ProviderAIExternal-secrets External Secrets OperatorAI | 10/10/2025 | 17/6/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider previously retrieved Kubernetes secrets… | |
| Aplazada | Alta (8.7) | 0.35% | — | Confidential Containers TrusteeAI | 9/10/2025 | 17/6/2026 | Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any… | |
| Aplazada | Media (6.3) | 0.52% | — | Rust-lang RustAI | 1/10/2025 | 17/6/2026 | Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle path separators, causing the standard library's Path API to ignore path components separated by backslashes. Due to this, programs compiled for Cygwin that validate paths could misbehave, potentially… | |
| Aplazada | Media (6.1) | 0.12% | — | Trust ReviewsAI | 27/9/2025 | 17/6/2026 | The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the feed_save function. This makes it possible for unauthenticated… |