Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.0% | — | Agentfront Enclave | 25/2/2026 | 17/6/2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1. | |
| Analizada | Media (6.4) | 0.21% | — | Agentfront Enclave | 6/2/2026 | 17/6/2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm… | |
| Analizada | Crítica (10) | 0.76% | — | Agentfront Enclave | 14/1/2026 | 17/6/2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Fortanix Enclave OSAI | 10/1/2025 | 17/6/2026 | Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals. | |
| Modificada | Alta (7.5) | 0.69% | — | Openenclave | 17/7/2023 | 17/6/2026 | Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted Execution Environments, also known as Enclaves. There are two issues that are mitigated in version 0.19.3. First, Open Enclave SDK does not properly sanitize the `MXCSR` register on enclave entry.… | |
| Modificada | Media (6.7) | 0.90% | — | Microsoft Open Enclave Software Development KIT | 14/7/2021 | 10/8/2026 | Open Enclave SDK Elevation of Privilege Vulnerability | |
| Modificada | Media (6.7) | 0.30% | — | Nitro Enclaves Project Nitro EnclavesRedhat Enterprise LinuxFedoraproject Fedora | 1/6/2021 | 17/6/2026 | A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system. | |
| Modificada | Media (6.8) | 0.64% | — | Openenclave | 14/10/2020 | 17/6/2026 | In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully exploited the vulnerability could read privileged data from the enclave heap across… | |
| Modificada | Media (5.3) | 0.33% | — | Openenclave | 15/7/2020 | 17/6/2026 | In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host application. By violating the Linux System V Application Binary Interface (ABI) for such operations, a host app can compromise the execution integrity of some x87 FPU operations in an enclave. Depending… | |
| Modificada | Media (5.5) | 1.6% | — | Microsoft Open Enclave Software Development KIT | 12/11/2019 | 17/6/2026 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | |
| Modificada | Media (5.5) | 2.1% | — | Microsoft Open Enclave Software Development KIT | 10/10/2019 | 17/6/2026 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | |
| Modificada | Media (5.5) | 1.6% | — | Microsoft Open Enclave Software Development KIT | 9/4/2019 | 17/6/2026 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. |