Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.58% | — | Agoric SESAI | 18/4/2025 | 17/6/2026 | SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web extensions using `ses` and the Compartment API to evaluate third-party code in an isolated execution environment that have also elsewhere… | |
| Modificada | Crítica (9.8) | 1.3% | — | Agoric SES | 8/8/2023 | 17/6/2026 | SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the confinement of guest applications under… | |
| Modificada | Crítica (10) | 1.8% | — | Agoric Realms-shim | 10/1/2022 | 17/6/2026 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | |
| Modificada | Crítica (9.8) | 1.8% | — | Agoric Realms-shim | 10/1/2022 | 17/6/2026 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |