Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.28% | — | ARM Mbed TLSARM Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is… | |
| Analizada | Media (5.1) | 0.27% | — | ARM Mbed TLSARM Tf-psa-crypto | 1/4/2026 | 17/6/2026 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | |
| Analizada | Media (6.7) | 0.15% | — | ARM Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). | |
| Analizada | Alta (7.7) | 0.18% | — | ARM Mbed TLSTrustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). | |
| Analizada | Crítica (9.8) | 0.60% | — | Trustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. |