Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.30% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked from one instance to the next. The implementation of resetting the virtual memory… | |
| Analizada | Crítica (9) | 0.49% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox. This vulnerability requires use of the Winch compiler… | |
| Analizada | Baja (1) | 0.12% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of embedder API calls made by the host. Specifically, the following steps must occur to… | |
| Modificada | Crítica (9) | 0.39% | — | Bytecodealliance Wasmtime | 9/4/2026 | 15/7/2026 | Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a guest WebAssembly… | |
| Analizada | Media (5.9) | 0.42% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, and cause the host… | |
| Analizada | Baja (2.3) | 0.38% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the table.size instruction. This bug could lead to disclosing data on the host's stack to… | |
| Analizada | Media (4.1) | 0.26% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When signals-based-traps are disabled this can result in a uncaught… | |
| Analizada | Media (5.6) | 0.39% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic which can happen when a flags-typed component model value is lifted with the Val type. If bits are set outside of the set of flags the component model specifies that these bits should be ignored but… | |
| Analizada | Media (5.9) | 0.42% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 or latin1+utf16 encodings improperly verified the alignment of reallocated strings. This meant that unaligned pointers could be passed to the host for… | |
| Analizada | Media (6.9) | 0.46% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. Specifically the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Bigsk1 Openai-realtime-uiAI | 8/4/2026 | 24/7/2026 | A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulation of the argument Query results in server-side request forgery. The attack can… | |
| Aplazada | Media (5.3) | 0.26% | — | Shiptime Discounted Shipping RatesAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1. | |
| Analizada | Alta (7.5) | 0.66% | — | Fedify/fedifyFedify/vocab-runtime | 6/4/2026 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.… | |
| Aplazada | Alta (7.2) | 0.32% | — | Wp-buy Visitor Traffic Real Time StatisticsAI | 4/4/2026 | 24/7/2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Crítica (9.2) | 0.82% | — | Hackerbay Oneuptime | 2/4/2026 | 6/10/2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a… | |
| Analizada | Alta (8.1) | 0.34% | — | Hackerbay Oneuptime | 2/4/2026 | 6/10/2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first <Signature> element in the XML DOM using… | |
| Analizada | Crítica (9.2) | 0.67% | — | Hackerbay Oneuptime | 2/4/2026 | 6/10/2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are… | |
| Analizada | Crítica (9.1) | 0.50% | — | Hackerbay Oneuptime | 2/4/2026 | 6/10/2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42. | |
| Analizada | Media (5.5) | 0.32% | — | Microchip Timeprovider 4100 Firmware | 28/3/2026 | 12/8/2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0. | |
| Pendiente de análisis | Alta (7) | 0.18% | — | Thales Sentinel LDK RuntimeAI | 27/3/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22. | |
| Analizada | Crítica (9.9) | 1.1% | — | Hackerbay Oneuptime | 26/3/2026 | 7/10/2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is executed in… | |
| Analizada | Media (6.5) | 0.41% | — | Solidtime | 24/3/2026 | 17/6/2026 | solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index() endpoint correctly… | |
| Pendiente de análisis | Alta (8.8) | 0.43% | — | Codesys Control Runtime SystemAI | 24/3/2026 | 17/6/2026 | A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution. | |
| Pendiente de análisis | Crítica (10) | 0.43% | — | Timeplus-io ProtonAI | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16. | |
| Analizada | Alta (8.7) | 0.20% | — | Hackerbay Oneuptime | 20/3/2026 | 7/10/2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send… |