Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 58 respecto a la semana anterior
Críticas / altas1456▲ 346 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.64% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames… | |
| Analizada | Alta (7.1) | 0.30% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, because… | |
| Analizada | Alta (7) | 0.37% | — | Amazon ToughAmazon Tuftool | 24/4/2026 | 17/6/2026 | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role metadata. We recommend… |