Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Digitalguardian Removable Media EncryptionAI | 15/11/2024 | 17/6/2026 | A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data. | |
| Analizada | Media (4.6) | 0.25% | — | Arnesonium Openpgp Form Encryption | 13/7/2024 | 17/6/2026 | The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Alta (8.7) | 0.24% | — | Mendix EncryptionAI | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the module define a specific hard-coded default value for the EncryptionKey constant, which is used in projects where no individual EncryptionKey was specified. This could allow to an attacker to decrypt… | |
| Aplazada | Alta (7.5) | 0.44% | — | Wpencryption WP EncryptionAI | 9/4/2024 | 17/6/2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0 via exposed Private key files. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Modificada | Crítica (9.8) | 1.0% | — | Yealink Configuration Encryption Tool | 23/2/2024 | 17/6/2026 | An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations. | |
| Analizada | Alta (7.5) | 0.44% | — | Yealink Configuration Encryption Tool | 20/2/2024 | 17/6/2026 | Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary. | |
| Modificada | Alta (7.8) | 0.09% | — | Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server | 6/2/2024 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in… | |
| Modificada | Media (5.3) | 0.21% | — | Amazon AWS Encryption SDK | 19/1/2024 | 14/7/2026 | AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. | |
| Modificada | Alta (7.3) | 0.15% | — | Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server | 16/11/2023 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a… | |
| Modificada | Media (6.5) | 0.49% | — | Nextcloud End-to-end Encryption | 23/6/2023 | 17/6/2026 | Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4… | |
| Modificada | Media (6.8) | 0.20% | — | Trendmicro Trend Micro Endpoint Encryption | 22/3/2023 | 17/6/2026 | A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker… | |
| Modificada | Media (6.5) | 0.20% | — | Eset Endpoint EncryptionEset Full Disk Encryption | 6/9/2022 | 17/6/2026 | The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD. | |
| Modificada | Media (6.1) | 0.39% | — | IBM Guardium Data Encryption | 10/5/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213862. | |
| Modificada | Media (5) | 0.35% | — | IBM Guardium Data Encryption | 6/5/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. IBM X-Force ID: 213865. | |
| Modificada | Alta (7.5) | 0.86% | — | IBM Guardium Data Encryption | 6/5/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213860. | |
| Modificada | Media (5.3) | 0.50% | — | IBM Guardium Data Encryption | 5/5/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 213855. | |
| Modificada | Media (5.3) | 0.58% | — | IBM Guardium Data Encryption | 10/3/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down. IBM X-Force 213863. | |
| Modificada | Alta (8.8) | 0.49% | — | IBM Guardium Data Encryption | 10/3/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software. IBM X-Force ID: 213858. | |
| Modificada | Media (5.9) | 0.51% | — | IBM Guardium Data Encryption | 18/2/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID:… | |
| Modificada | Media (5.3) | 0.54% | — | IBM Guardium Data Encryption | 2/2/2022 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856. | |
| Modificada | Alta (7.8) | 0.20% | — | Mcafee Drive Encryption | 10/11/2021 | 17/6/2026 | DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder. | |
| Modificada | Alta (7.8) | 0.15% | — | Mcafee Drive Encryption | 1/10/2021 | 17/6/2026 | Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer. | |
| Modificada | Alta (7.4) | 50% | — | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Media (4.9) | 0.54% | — | IBM Guardium Data Encryption | 12/7/2021 | 17/6/2026 | IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216. |