Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Trusted Shops Easy Integration FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | |
| Aplazada | Media (5.5) | 0.40% | — | Trusteddomain OpendmarcAI | 29/9/2026 | 29/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used.… | |
| Aplazada | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 29/9/2026 | 29/9/2026 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried… | |
| Aplazada | Baja (2.1) | 0.13% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit… | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could… | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of… | |
| Pendiente de análisis | Media (5.5) | 0.31% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely.… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.67% | — | Trusted Domain Project OpenarcAI | 28/9/2026 | 28/9/2026 | A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch… | |
| Pendiente de análisis | Media (5.5) | 0.37% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the… | |
| Aplazada | Baja (2.3) | 0.21% | — | RustdeskAI | 25/9/2026 | 30/9/2026 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the… | |
| Aplazada | Media (5.3) | 0.18% | — | RustdeskAI | 25/9/2026 | 30/9/2026 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents… | |
| Pendiente de análisis | Alta (7.1) | 0.09% | — | Dell Trusted Device ClientAI | 24/9/2026 | 26/9/2026 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Altera Trusted FirmwareAI | 24/9/2026 | 24/9/2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Trustedlogin ConnectorAI | 23/9/2026 | 23/9/2026 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | |
| Pendiente de análisis | Media (5.5) | 0.17% | — | Virustotal YaraAI | 22/9/2026 | 24/9/2026 | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate. |