Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.64% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames… | |
| Analizada | Alta (7.1) | 0.30% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because… | |
| Analizada | Alta (7) | 0.37% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata. We recommend… | |
| Modificada | Media (5.7) | 0.33% | — | Amazon Tough | 27/3/2025 | 17/6/2026 | During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure… | |
| Modificada | Media (5.7) | 0.33% | — | Amazon Tough | 27/3/2025 | 17/6/2026 | During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new… | |
| Modificada | Media (5.7) | 0.33% | — | Amazon Tough | 27/3/2025 | 17/6/2026 | Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later… | |
| Modificada | Media (5.7) | 0.33% | — | Amazon Tough | 27/3/2025 | 17/6/2026 | Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or… | |
| Modificada | Crítica (9.8) | 2.5% | — | Salesforce Tough-cookie | 1/7/2023 | 17/6/2026 | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. | |
| Modificada | Media (6.5) | 1.3% | — | Amazon Tough | 19/10/2021 | 17/6/2026 | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded,… | |
| Modificada | Alta (8.1) | 1.1% | — | Amazon Tough | 19/10/2021 | 17/6/2026 | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could… | |
| Modificada | Alta (8.6) | 1.4% | — | Amazon Tough | 9/7/2020 | 17/6/2026 | The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in… | |
| Modificada | Media (5.3) | 2.4% | — | Salesforce Tough-cookieIBM API ConnectRedhat Openshift Container Platform | 5/9/2018 | 17/6/2026 | NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0. | |
| Modificada | Alta (7.5) | 3.3% | — | Salesforce Tough-cookie | 4/10/2017 | 17/6/2026 | A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU. | |
| Modificada | Alta (7.5) | 1.6% | — | Toughtomato COM Ttvideo | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php. |