Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.18%—ARM Trusted Firmware-aAI23/11/202517/6/2026
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
AnalizadaMedia (5.8)0.16%—AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a13/8/202417/6/2026
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
AplazadaMedia (4.4)0.22%—ARM Trusted Firmware-aAI21/2/202417/6/2026
Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the…
ModificadaAlta (7.4)0.63%—Trustedfirmware Trusted Firmware-a16/1/202317/6/2026
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
ModificadaMedia (5.3)1.4%—Trustedfirmware Trusted Firmware-a30/1/201917/6/2026
ARM Trusted Firmware-A allows information disclosure.
AnalizadaAlta (7.5)1.9%—Trustedfirmware Trusted Firmware-a18/12/201817/6/2026
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
AnalizadaAlta (7)0.79%—Trustedfirmware Trusted Firmware-a20/9/201717/6/2026
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.
AnalizadaAlta (7.5)1.0%—Trustedfirmware Trusted Firmware-a7/6/201717/6/2026
In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers.
AnalizadaAlta (8.1)0.89%—Trustedfirmware Trusted Firmware-a7/6/201717/6/2026
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).