Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Webassembly WabtAIRlboxAIWasmbind Wasm BoxcAIMozilla FirefoxAI | 12/9/2026 | 22/9/2026 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails,… | |
| Aplazada | Media (6.9) | 0.15% | — | Craigjbass ClearancekitAI | 20/7/2026 | 23/7/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clearancekit/store.db`) is stored in the macOS System Keychain. The key was created via the two-step pattern… | |
| Aplazada | Media (6.9) | 0.15% | — | Craigjbass ClearancekitAI | 20/7/2026 | 23/7/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store (`/Library/Application Support/clearancekit/store.db`) is verified using an ECDSA signature stored in the `data_signatures` table. The signed… | |
| Aplazada | Media (5.3) | 0.31% | — | DumbasssetsAI | 18/5/2026 | 14/7/2026 | DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers can create or update assets with HTML or… | |
| Analizada | Baja (1.9) | 0.19% | — | Webassembly Binaryen | 11/5/2026 | 23/7/2026 | A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and… | |
| Analizada | Alta (8.2) | 0.15% | — | Craigjbass Clearancekit | 21/4/2026 | 17/6/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any process running as… | |
| Analizada | Alta (8.4) | 0.15% | — | Craigjbass Clearancekit | 21/4/2026 | 17/6/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global… | |
| Aplazada | Media (6.8) | 0.15% | — | Craigjbass ClearancekitAI | 10/4/2026 | 17/6/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail policies. The destination… | |
| Analizada | Media (6.3) | 0.15% | — | Craigjbass Clearancekit | 31/3/2026 | 24/7/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined file-access rules… | |
| Analizada | Alta (8.4) | 0.15% | — | Craigjbass Clearancekit | 26/3/2026 | 17/6/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types — ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE — were not intercepted by ClearanceKit's opfilter system extension, allowing local processes to… | |
| Analizada | Alta (8.7) | 0.15% | — | Craigjbass Clearancekit | 26/3/2026 | 17/6/2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional file operation event… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex BasseinAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bassein bassein allows PHP Local File Inclusion.This issue affects Bassein: from n/a through <= 1.0.15. | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Wabt | 1/1/2026 | 1/10/2026 | A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Wabt | 1/1/2026 | 1/10/2026 | A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Binaryen | 19/12/2025 | 17/6/2026 | A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index leads to null pointer dereference. Local… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Binaryen | 19/12/2025 | 17/6/2026 | A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.1) | 0.15% | — | Nikias Bassen UsbmuxdAI | 10/12/2025 | 17/6/2026 | A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba. | |
| Analizada | Alta (7.4) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is… | |
| Analizada | Media (5.5) | 0.19% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4. | |
| Analizada | Baja (2.1) | 0.37% | — | Bytecodealliance Webassembly Micro Runtime | 16/9/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address pointer) is greater… | |
| Analizada | Media (6.9) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 29/7/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP… | |
| Analizada | Baja (1.9) | 0.24% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local host. The exploit has… | |
| Analizada | Baja (1.9) | 0.23% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and… | |
| Analizada | Baja (1.9) | 0.23% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7) | 0.28% | — | Bytecodealliance Webassembly Micro Runtime | 15/5/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following… |