Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
11.348 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.35% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking… | |
| Analizada | Crítica (9.3) | 0.27% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data. | |
| Analizada | Alta (8.7) | 0.44% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data… | |
| Analizada | Alta (8.7) | 0.32% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords. | |
| Analizada | Crítica (9.3) | 0.68% | — | Jahlives Openssl Encrypt | 17/8/2026 | 31/8/2026 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to… | |
| Analizada | Media (6.9) | 0.11% | — | Jahlives Openssl Encrypt | 17/8/2026 | 10/9/2026 | openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256… | |
| Analizada | Alta (8.7) | 0.26% | — | Jahlives Openssl Encrypt | 17/8/2026 | 3/9/2026 | openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal… | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Baja (2.1) | 0.45% | — | Alaev SEO Tools ExtensionAI | 17/8/2026 | 20/8/2026 | A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Aplazada | Baja (2.9) | 0.63% | — | Opensourcepos Open Source Point OF SaleAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Dancer2 Plugin Auth ExtensibleAI | 15/8/2026 | 26/8/2026 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from… | |
| Pendiente de análisis | Media (6.3) | 0.30% | — | Openstack IronicAI | 14/8/2026 | 1/9/2026 | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. | |
| Analizada | Alta (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… | |
| Analizada | Alta (7.5) | 0.42% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,… | |
| Analizada | Alta (7.5) | 0.23% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized… | |
| Analizada | Alta (8.2) | 0.46% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.… | |
| Analizada | Media (4.4) | 0.33% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to… | |
| Analizada | Media (6.5) | 0.31% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle… | |
| Analizada | Media (5.4) | 0.29% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from… | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Openstack OctaviaAI | 14/8/2026 | 9/9/2026 | OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected. | |
| Analizada | Media (4.4) | 0.15% | — | Redhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 31/8/2026 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. | |
| Modificada | Media (5.5) | 0.16% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 2/10/2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This… | |
| Pendiente de análisis | Alta (8.7) | 1.00% | — | Opensearch SQL PluginAIApache SparkAI | 13/8/2026 | 14/8/2026 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint. | |
| Pendiente de análisis | Alta (7.6) | 0.19% | — | RsyncAIRsync-sslAIOpensslAIStunnelAI | 13/8/2026 | 8/9/2026 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS… | |
| Pendiente de análisis | Alta (7.5) | 0.73% | — | OpensslAI | 13/8/2026 | 28/8/2026 | Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster… |