Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Webassembly WabtAIRlboxAIWasmbind Wasm BoxcAIMozilla FirefoxAI | 12/9/2026 | 22/9/2026 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails,… | |
| Analizada | Baja (1.9) | 0.19% | — | Webassembly Binaryen | 11/5/2026 | 23/7/2026 | A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Wabt | 1/1/2026 | 1/10/2026 | A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Wabt | 1/1/2026 | 1/10/2026 | A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Binaryen | 19/12/2025 | 17/6/2026 | A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index leads to null pointer dereference. Local… | |
| Modificada | Baja (1.9) | 0.21% | — | Webassembly Binaryen | 19/12/2025 | 17/6/2026 | A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed… | |
| Analizada | Alta (7.4) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is… | |
| Analizada | Media (5.5) | 0.19% | — | Bytecodealliance Webassembly Micro Runtime | 25/11/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4. | |
| Analizada | Baja (2.1) | 0.37% | — | Bytecodealliance Webassembly Micro Runtime | 16/9/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address pointer) is greater… | |
| Analizada | Media (6.9) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 29/7/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP… | |
| Analizada | Baja (1.9) | 0.24% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local host. The exploit has… | |
| Analizada | Baja (1.9) | 0.23% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and… | |
| Analizada | Baja (1.9) | 0.23% | — | Webassembly Wabt | 19/6/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7) | 0.28% | — | Bytecodealliance Webassembly Micro Runtime | 15/5/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following… | |
| Analizada | Baja (2.3) | 0.60% | — | Webassembly Binary Toolkit | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of… | |
| Analizada | Baja (2.3) | 0.50% | — | Webassembly Wabt | 21/3/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely.… | |
| Analizada | Media (5.3) | 0.57% | — | Webassembly Wabt | 17/3/2025 | 17/6/2026 | A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to heap-based buffer… | |
| Analizada | Alta (7.5) | 0.51% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | |
| Analizada | Alta (7.8) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | |
| Analizada | Alta (7.5) | 0.76% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |
| Analizada | Media (6.2) | 0.33% | — | Bytecodealliance Webassembly Micro Runtime | 6/5/2024 | 17/6/2026 | A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c. | |
| Modificada | Media (5.5) | 0.32% | — | Bytecodealliance Webassembly Micro Runtime | 31/12/2023 | 17/6/2026 | Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled. | |
| Modificada | Alta (7.5) | 1.0% | — | Bytecodealliance Webassembly Micro Runtime | 22/11/2023 | 9/7/2026 | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c. | |
| Modificada | Media (5.5) | 0.21% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault. | |
| Modificada | Media (5.5) | 0.27% | — | Webassembly Binary Toolkit | 23/10/2023 | 17/6/2026 | WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault. |