Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | SAP Commoncryptolib | 14/9/2021 | 17/6/2026 | SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system. | |
| Modificada | Media (5.9) | 1.2% | — | Cryptopp Crypto++Fedoraproject Fedora | 6/9/2021 | 17/6/2026 | The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can… | |
| Modificada | Media (4.7) | 0.21% | — | Intel Integrated Performance Primitives CryptographyIntel SGX DcapIntel SGX PSWIntel SGX SDK | 9/6/2021 | 17/6/2026 | Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.9) | 1.5% | — | Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java | 20/5/2021 | 17/6/2026 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic… | |
| Modificada | Alta (7.8) | 0.38% | — | Utimaco Block-safe FirmwareUtimaco Cryptoserver CP5 FirmwareUtimaco Cryptoserver CP5 Vs-nfd FirmwareUtimaco Paymentserver Firmware+2 | 18/3/2021 | 17/6/2026 | Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak… | |
| Modificada | Crítica (9.1) | 6.7% | — | Cryptography.io CryptographyFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment | 7/2/2021 | 17/6/2026 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class. | |
| Modificada | Media (5.9) | 0.93% | — | Stm32cubef0Stm32cubef1Stm32cubef2Stm32cubef3+18 | 20/1/2021 | 9/7/2026 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library,… | |
| Modificada | Media (5.9) | 0.87% | — | Ietf Public KEY Cryptography Standards #1Microchip Libraries FOR Applications | 19/1/2021 | 9/7/2026 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in… | |
| Modificada | Media (5.9) | 1.8% | — | M2crypto Project M2cryptoRedhat VirtualizationRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2021 | 17/6/2026 | A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Media (5.9) | 2.5% | — | Cryptography.io CryptographyOracle Communications Cloud Native Core Network Function Cloud Native Environment | 11/1/2021 | 17/6/2026 | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext. | |
| Modificada | Alta (7.5) | 1.4% | — | Ansible Collections Project Community.crypto | 29/10/2020 | 17/6/2026 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality | |
| Modificada | Media (5.5) | 0.36% | — | Cryptopro CSP | 23/10/2020 | 17/6/2026 | CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation. | |
| Modificada | Alta (7.8) | 0.41% | — | Cryptopro CSP | 23/10/2020 | 17/6/2026 | CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space. | |
| Modificada | Media (6.8) | 0.60% | — | Microchip Cryptoauthlib | 22/10/2020 | 17/6/2026 | Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2). | |
| Modificada | Media (6.8) | 0.60% | — | Microchip Cryptoauthlib | 22/10/2020 | 17/6/2026 | Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2). | |
| Modificada | Baja (2.5) | 0.23% | — | Amazon AWS S3 Crypto SDK | 11/8/2020 | 17/6/2026 | A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a… | |
| Modificada | Media (5.6) | 0.35% | — | Amazon AWS S3 Crypto SDK | 11/8/2020 | 17/6/2026 | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket and can observe whether or not an… | |
| Modificada | Crítica (9.8) | 2.6% | — | Microsoft Research Javascript Cryptography Library | 15/4/2020 | 17/6/2026 | A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a server’s private ECC key (a key leakage attack) or… | |
| Modificada | Media (5.9) | 1.7% | — | ARM Mbed CryptoARM Mbed TLSFedoraproject FedoraDebian Linux | 24/3/2020 | 17/6/2026 | Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Jenkins Cryptomove | 9/3/2020 | 17/6/2026 | Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins. | |
| Modificada | Media (4.7) | 0.34% | — | ARM Mbed CryptoARM Mbed TLSFedoraproject FedoraDebian Linux | 23/1/2020 | 17/6/2026 | The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks. | |
| Modificada | Crítica (9.8) | 1.5% | — | Cryptocat Project Cryptocat | 14/11/2019 | 16/6/2026 | Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. | |
| Modificada | Media (6.1) | 1.5% | — | Cryptocat Project Cryptocat | 14/11/2019 | 16/6/2026 | A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22. | |
| Modificada | Media (6.1) | 1.7% | — | Cryptocat Project Cryptocat | 14/11/2019 | 16/6/2026 | An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165. |