Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are… | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Alta (7.1) | 0.30% | — | Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+6 | 14/11/2021 | 17/6/2026 | In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. | |
| Modificada | Alta (7.2) | 0.50% | — | Wibu Codemeter Runtime | 26/11/2014 | 17/6/2026 | Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Media (5) | 4.9% | — | Wibu Codemeter Runtime | 13/1/2012 | 16/6/2026 | Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attackers to cause a denial of service (CodeMeter.exe crash) via certain crafted packets to TCP port 22350. |