Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%—SAP Commoncryptolib14/9/202117/6/2026
SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.
ModificadaMedia (5.9)1.2%—Cryptopp Crypto++Fedoraproject Fedora6/9/202117/6/2026
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can…
ModificadaMedia (4.7)0.21%—Intel Integrated Performance Primitives CryptographyIntel SGX DcapIntel SGX PSWIntel SGX SDK9/6/202117/6/2026
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
ModificadaMedia (5.9)1.5%—Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java20/5/202117/6/2026
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic…
ModificadaAlta (7.8)0.38%—Utimaco Block-safe FirmwareUtimaco Cryptoserver CP5 FirmwareUtimaco Cryptoserver CP5 Vs-nfd FirmwareUtimaco Paymentserver Firmware+218/3/202117/6/2026
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak…
ModificadaCrítica (9.1)6.7%—Cryptography.io CryptographyFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment7/2/202117/6/2026
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
ModificadaMedia (5.9)0.93%—Stm32cubef0Stm32cubef1Stm32cubef2Stm32cubef3+1820/1/20219/7/2026
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library,…
ModificadaMedia (5.9)0.87%—Ietf Public KEY Cryptography Standards #1Microchip Libraries FOR Applications19/1/20219/7/2026
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in…
ModificadaMedia (5.9)1.8%—M2crypto Project M2cryptoRedhat VirtualizationRedhat Enterprise LinuxFedoraproject Fedora12/1/202117/6/2026
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
ModificadaMedia (5.9)2.5%—Cryptography.io CryptographyOracle Communications Cloud Native Core Network Function Cloud Native Environment11/1/202117/6/2026
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
ModificadaAlta (7.5)1.4%—Ansible Collections Project Community.crypto29/10/202017/6/2026
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
ModificadaMedia (5.5)0.36%—Cryptopro CSP23/10/202017/6/2026
CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.
ModificadaAlta (7.8)0.41%—Cryptopro CSP23/10/202017/6/2026
CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space.
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
ModificadaBaja (2.5)0.23%—Amazon AWS S3 Crypto SDK11/8/202017/6/2026
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a…
ModificadaMedia (5.6)0.35%—Amazon AWS S3 Crypto SDK11/8/202017/6/2026
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket and can observe whether or not an…
ModificadaCrítica (9.8)2.6%—Microsoft Research Javascript Cryptography Library15/4/202017/6/2026
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a server’s private ECC key (a key leakage attack) or…
ModificadaMedia (5.9)1.7%—ARM Mbed CryptoARM Mbed TLSFedoraproject FedoraDebian Linux24/3/202017/6/2026
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaAlta (8.8)2.0%—Jenkins Cryptomove9/3/202017/6/2026
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.
ModificadaMedia (4.7)0.34%—ARM Mbed CryptoARM Mbed TLSFedoraproject FedoraDebian Linux23/1/202017/6/2026
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
ModificadaCrítica (9.8)1.5%—Cryptocat Project Cryptocat14/11/201916/6/2026
Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
ModificadaMedia (6.1)1.5%—Cryptocat Project Cryptocat14/11/201916/6/2026
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
ModificadaMedia (6.1)1.7%—Cryptocat Project Cryptocat14/11/201916/6/2026
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
Orbitaley — Vulnerabilidades