Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.16% | — | IBM Trusteer Rapport | 10/3/2026 | 17/6/2026 | IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute… | |
| Aplazada | Alta (8.7) | 0.35% | — | Confidential Containers TrusteeAI | 9/10/2025 | 17/6/2026 | Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any… | |
| Aplazada | Alta (8.1) | 0.34% | — | Confidential Computing Consortium TrusteeAI | 8/11/2024 | 17/6/2026 | Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still verify it successfully. In the payload of… | |
| Analizada | Crítica (9.8) | 0.46% | — | IBM Trusteer Android SDK FOR MobileIBM Trusteer IOS SDK FOR Mobile | 17/2/2024 | 17/6/2026 | An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535. | |
| Modificada | Media (5.3) | 0.98% | — | IBM Security Trusteer Pinpoint Detect | 16/9/2020 | 17/6/2026 | IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X-Force ID: 187371. | |
| Modificada | Media (4.9) | 0.45% | — | Cloudera ManagerCloudera Navigator KEY Trustee KMS | 7/6/2019 | 17/6/2026 | In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS ACL values for these commands are… | |
| Modificada | Crítica (9.8) | 0.72% | — | Cloudera KEY Trustee Server | 23/3/2017 | 17/6/2026 | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key. | |
| Modificada | Baja (2.1) | 0.98% | — | Bray Systems Linux Trustees | 10/4/2000 | 16/6/2026 | The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name. |