Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.3%💥 ExploitBlocksera Cryptocurrency Widgets Pack15/12/202217/6/2026
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
ModificadaMedia (6.1)0.60%—Premium-themes Cryptocurrency Pricing List AND Ticker10/10/202217/6/2026
The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.5)0.26%—IBM Common Cryptographic Architecture23/9/202217/6/2026
IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.
ModificadaMedia (6.7)0.98%💥 PoCKidan Cryptopro Securedisk FOR BitlockerRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this…
ModificadaMedia (5.5)0.27%—Opencryptoki Project Opencryptoki23/8/202217/6/2026
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
ModificadaMedia (5.3)1.4%—Evmos EthermintKavaCrypto CronosEvmos5/8/202217/6/2026
Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared…
ModificadaCrítica (9.8)1.00%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.
ModificadaCrítica (9.8)0.51%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
ModificadaCrítica (9.8)1.0%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
ModificadaCrítica (9.8)0.72%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
ModificadaAlta (8.1)0.78%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
ModificadaCrítica (9.8)1.1%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
ModificadaCrítica (9.8)1.2%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
ModificadaCrítica (9.8)1.1%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.
ModificadaCrítica (9.8)1.2%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
ModificadaAlta (7.5)0.76%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle Retail Customer Insights11/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.
ModificadaCrítica (9.8)2.0%—Pypi Cryptoasset-data-downloader24/6/202217/6/2026
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaCrítica (9.1)0.97%—Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+8814/3/202217/6/2026
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows…
ModificadaAlta (7.8)0.56%—Cryptomator19/2/202217/6/2026
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlements. An attacker can exploit this by creating a malicious .dylib file that can…
ModificadaMedia (5.5)0.24%—Intel Integrated Performance Primitives Cryptography9/2/202217/6/2026
Improper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaCrítica (9.8)0.75%—Crypto2 Project Crypto227/12/202117/6/2026
An issue was discovered in the crypto2 crate through 2021-10-08 for Rust. During Chacha20 encryption and decryption, an unaligned read of a u32 may occur.
ModificadaAlta (7.5)1.3%—Crypto CronosCrypto EthermintCrypto Evmos21/12/202117/6/2026
Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds.…
ModificadaMedia (6.6)0.57%—Crypto API Toolkit FOR Intel SGX17/11/202117/6/2026
Time-of-check time-of-use vulnerability in the Crypto API Toolkit for Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.3)2.0%—Cryptopp Crypto++4/11/202117/6/2026
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks. NOTE: this report is…
Orbitaley — Vulnerabilidades