Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
Pendiente de análisisAlta (8.3)0.11%—Altera Trusted FirmwareAI24/9/202624/9/2026
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
AplazadaAlta (7)0.17%—ARM Trusted Firmware-mAIInfineon Psoc64AIRaspberrypi Rp2350AI26/8/20269/9/2026
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AplazadaAlta (8.6)0.18%—ARM Trusted Firmware-aAI23/11/202517/6/2026
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
AplazadaAlta (8.6)0.45%—Trustedfirmware Trusted Firmware-mAIARM McubootAI30/7/202517/6/2026
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components…
AplazadaCrítica (9.8)0.81%—Trustedfirmware Trusted Firmware-mAI9/10/202417/6/2026
An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer pointer and a buffer length field. After a…
ModificadaMedia (4.7)0.29%—Trustedfirmware Trusted Firmware-m5/9/202417/6/2026
An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.
AnalizadaMedia (5.8)0.16%—AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a13/8/202417/6/2026
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
ModificadaMedia (6.7)0.22%—Renesas Arm-trusted-firmware8/7/202417/6/2026
Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.
ModificadaMedia (6.7)0.21%—Renesas Arm-trusted-firmware8/7/202417/6/2026
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program files https://github.Com/renesas-rcar/arm-trusted-firmware/blob/rcar_gen3_v2.5/drivers/renesas/common/io/i...…
AplazadaMedia (4.4)0.22%—ARM Trusted Firmware-aAI21/2/202417/6/2026
Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the…
AnalizadaBaja (2)0.14%—Renesas Arm-trusted-firmware19/2/202417/6/2026
During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_descs”. For each image, the bl2 reads the image length and destination from the image’s certificate. Because of the way of reading from the image, which base on 32-bit unsigned integer value, it can…
ModificadaAlta (7.5)0.39%—Trustedfirmware Trusted Firmware-m8/9/202317/6/2026
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the…
ModificadaAlta (7.4)0.63%—Trustedfirmware Trusted Firmware-a16/1/202317/6/2026
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
ModificadaAlta (7.8)0.42%—Trustedfirmware Trusted Firmware-m1/3/202217/6/2026
Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.
ModificadaMedia (5.9)1.2%—Trustedfirmware Trusted Firmware-m13/1/202217/6/2026
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.
AnalizadaMedia (5.5)3.1%⚠ Explotación activaTrustedfirmware Trusted Firmware-m25/5/202117/6/2026
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
AnalizadaAlta (7.5)1.8%—Trustedfirmware Trusted Firmware-m21/5/202117/6/2026
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.