Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.14% | — | Elegro Crypto PaymentAI | 6/10/2026 | 6/10/2026 | The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been… | |
| Aplazada | Baja (2) | 0.19% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 6/10/2026 | A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.28% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 6/10/2026 | A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.29% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 6/10/2026 | A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.29% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 6/10/2026 | A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Nasa CryptolibAI | 17/9/2026 | 18/9/2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. | |
| Pendiente de análisis | Media (5.9) | 0.66% | — | Latchset JwcryptoAI | 16/9/2026 | 16/9/2026 | A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply a JWK with a large key_ops array to an application that passes… | |
| Aplazada | Crítica (10) | 0.50% | 💥 PoC | Cryptopayment GatewayAI | 13/9/2026 | 14/9/2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored… | |
| Aplazada | Media (6.9) | 0.31% | — | Matrix-sdk-cryptoAI | 11/9/2026 | 30/9/2026 | matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the… | |
| Aplazada | Media (5.9) | 0.33% | — | Mirage-crypto-ecAI | 9/9/2026 | 9/9/2026 | An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret. | |
| Aplazada | Media (4.3) | 0.36% | — | Mirage-crypto-ecAI | 9/9/2026 | 14/9/2026 | An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points. | |
| Aplazada | Media (4.3) | 0.23% | — | Mirage-crypto-pkAI | 9/9/2026 | 9/9/2026 | An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption. | |
| Aplazada | Media (6.2) | 0.15% | — | Mirage-crypto-ecAI | 9/9/2026 | 9/9/2026 | An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key. | |
| Aplazada | Media (6.2) | 0.11% | — | Mirage-cryptoAI | 9/9/2026 | 9/9/2026 | An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the… | |
| Pendiente de análisis | Media (5.9) | 0.13% | — | Latchset JwcryptoAI | 3/9/2026 | 8/9/2026 | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid)… | |
| Analizada | Alta (7.5) | 0.43% | — | Golang Crypto | 2/9/2026 | 4/9/2026 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet… | |
| Analizada | Alta (7.5) | 0.50% | — | Golang Crypto | 2/9/2026 | 4/9/2026 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of… | |
| Pendiente de análisis | Media (5.9) | 0.41% | — | Latchset JwcryptoAI | 28/8/2026 | 31/8/2026 | A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for… | |
| Aplazada | Media (5.7) | 0.17% | — | Kriptok Crypto AND Information Technologies Industry Trade INC CryptosimAI | 18/8/2026 | 26/8/2026 | Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229. | |
| Aplazada | Crítica (9.1) | 0.44% | — | JsbnAIJuneandgreen Sm-cryptoAI | 13/8/2026 | 18/9/2026 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random()… | |
| Aplazada | Media (5.9) | 0.09% | — | Oberon Microsystem AG Oberon PSA Crypto LibraryAI | 13/8/2026 | 26/8/2026 | Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations. | |
| Aplazada | Media (5.9) | 0.09% | — | Oberon Microsystem AG OcryptoAI | 13/8/2026 | 26/8/2026 | Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations. | |
| Aplazada | Crítica (9.1) | 0.20% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Alta (8.4) | 0.14% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.49% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. |