Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.78%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
AplazadaMedia (4.6)0.24%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
AplazadaAlta (7.2)0.67%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high…
AplazadaAlta (7.5)0.19%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaCrítica (9.8)0.65%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
AplazadaAlta (7.5)0.31%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.
AplazadaCrítica (9)0.55%💥 PoCCrypto-jsAI7/8/20269/9/2026
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator…
Pendiente de análisisAlta (8.7)0.25%—Python-cryptographyAI3/8/202610/9/2026
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an…
Pendiente de análisisMedia (6.9)0.31%—Python-cryptographyAI3/8/202610/9/2026
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier…
Pendiente de análisisAlta (8.2)0.27%—OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI3/8/202610/9/2026
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the…
Pendiente de análisisMedia (5.6)0.15%—S2opc CyclonecryptoAI29/7/202630/7/2026
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted
AnalizadaAlta (7.5)0.43%—Apple Swift-crypto23/7/20264/9/2026
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This…
AnalizadaBaja (2)0.16%—Rustcrypto Cmov17/7/202618/8/2026
RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. From 0.1.1 until 0.5.4, the aarch64 implementations of Cmov and CmovEq in cmov/src/backends/aarch64.rs assume high bits are zero-extended when…
AplazadaAlta (7.5)0.42%—ABC Crypto CheckoutAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
AplazadaCrítica (9.1)0.32%—Crypton-x509-validationAI11/6/202617/6/2026
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond…
AplazadaMedia (5.6)0.15%—S2opcAICyclonecryptoAI9/6/202623/7/2026
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
AplazadaMedia (6.4)0.32%—Cryptocurrency Prijsvergelijking WidgetAI27/5/202617/6/2026
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode() function, which renders the 'width' (and 'height') shortcode attribute directly into the style attribute of an…
AplazadaAlta (7.5)0.39%—Plainviewplugins MycryptocheckoutAI25/5/202624/7/2026
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.
AnalizadaMedia (5.3)0.52%—Golang Crypto22/5/202623/7/2026
For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
AnalizadaAlta (7.5)0.62%—Golang Crypto22/5/202623/7/2026
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
ModificadaCrítica (10)0.50%💥 PoCGolang Crypto22/5/202611/9/2026
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
ModificadaCrítica (9.1)0.65%—Golang Crypto22/5/202615/9/2026
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
AnalizadaCrítica (9.1)0.64%—Golang Crypto22/5/202623/7/2026
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.
ModificadaCrítica (9.1)0.49%—Golang Crypto22/5/202611/8/2026
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints…
ModificadaCrítica (9.1)0.72%—Golang Crypto22/5/202615/9/2026
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions.…
Orbitaley — Vulnerabilidades