Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.18% | — | ARM Trusted Firmware-aAI | 23/11/2025 | 17/6/2026 | The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC. | |
| Analizada | Media (5.8) | 0.16% | — | AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a | 13/8/2024 | 17/6/2026 | Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service. | |
| Aplazada | Media (4.4) | 0.22% | — | ARM Trusted Firmware-aAI | 21/2/2024 | 17/6/2026 | Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the… | |
| Modificada | Alta (7.4) | 0.63% | — | Trustedfirmware Trusted Firmware-a | 16/1/2023 | 17/6/2026 | Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state. | |
| Modificada | Media (5.3) | 1.4% | — | Trustedfirmware Trusted Firmware-a | 30/1/2019 | 17/6/2026 | ARM Trusted Firmware-A allows information disclosure. | |
| Analizada | Alta (7.5) | 1.9% | — | Trustedfirmware Trusted Firmware-a | 18/12/2018 | 17/6/2026 | In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. | |
| Analizada | Alta (7) | 0.79% | — | Trustedfirmware Trusted Firmware-a | 20/9/2017 | 17/6/2026 | The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow. | |
| Analizada | Alta (7.5) | 1.0% | — | Trustedfirmware Trusted Firmware-a | 7/6/2017 | 17/6/2026 | In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers. | |
| Analizada | Alta (8.1) | 0.89% | — | Trustedfirmware Trusted Firmware-a | 7/6/2017 | 17/6/2026 | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits). |