Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.40% | — | Trezor Safe 3AITrezor Safe 5AITrezor Safe 7AI | 21/7/2026 | 30/7/2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then… | |
| Aplazada | Media (4.6) | 0.24% | — | Trezor ONEAITrezor TAITrezor SafeAI | 14/4/2026 | 5/7/2026 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time execution and… | |
| Aplazada | Crítica (9.9) | 0.51% | — | Themify SidepaneAIThemify NewsyAIThemify FoloAIThemify EdminAI+5 | 6/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects… | |
| Aplazada | Alta (7.5) | 0.31% | — | CorezoidAI | 30/9/2025 | 17/6/2026 | Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unauthorized access to victim accounts. | |
| Analizada | Media (4.3) | 0.51% | — | Corezoid | 11/4/2024 | 17/6/2026 | Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL. | |
| Modificada | Crítica (9.8) | 1.3% | — | Trezor Bridge | 26/7/2021 | 17/6/2026 | A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. | |
| Modificada | Media (6.5) | 0.85% | — | Satoshilabs Trezor Model T FirmwareSatoshilabs Trezor ONE Firmware | 16/6/2020 | 17/6/2026 | BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1… | |
| Modificada | Media (4.2) | 0.37% | — | Trezor ONE Firmware | 8/8/2019 | 17/6/2026 | On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage… | |
| Modificada | Alta (7.8) | 1.3% | — | Andrey Cherezov Acweb | 31/12/2002 | 16/6/2026 | acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2. | |
| Modificada | Media (4.3) | 1.7% | — | Andrey Cherezov Acweb | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL. |