Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.43% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof demonstrating that a generated private key is sufficient to meet the unlinkability… | |
| Modificada | Alta (8.8) | 0.63% | — | Hyperledger Aries Cloud Agent | 11/1/2024 | 17/6/2026 | Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation `document.proof` was… | |
| Modificada | Media (6.5) | 0.52% | — | Hyperledger Fabric | 14/11/2023 | 17/6/2026 | Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the… | |
| Modificada | Media (5.4) | 0.76% | — | Hledger | 21/5/2023 | 17/6/2026 | An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function. | |
| Modificada | Alta (7.5) | 0.85% | — | Hyperledger Fabric | 12/11/2022 | 17/6/2026 | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabric with Raft prevents exploitation via a locking mechanism and a check for names that already exist. | |
| Modificada | Media (5.3) | 1.1% | — | Hyperledger Fabric | 18/8/2022 | 17/6/2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the… | |
| Modificada | Alta (7.5) | 2.1% | — | Hyperledger Fabric | 7/7/2022 | 17/6/2026 | Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the orderer node. A fix has been added in commit 0f1835949 which checks for missing consensus messages and returns an error to the consensus… | |
| Modificada | Media (6.8) | 1.1% | — | Ledgersmb | 14/10/2021 | 17/6/2026 | LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB… | |
| Modificada | Media (4.7) | 1.2% | — | LedgersmbDebian Linux | 23/8/2021 | 17/6/2026 | LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions. | |
| Modificada | Crítica (9.6) | 2.5% | — | LedgersmbDebian Linux | 23/8/2021 | 17/6/2026 | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | |
| Modificada | Crítica (9.6) | 3.2% | — | LedgersmbDebian Linux | 23/8/2021 | 17/6/2026 | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Subledger Accounting | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Inquiries). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting. Successful attacks… | |
| Modificada | Alta (8.1) | 0.99% | — | Oracle General Ledger | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful… | |
| Modificada | Media (6.5) | 1.0% | — | SAP Bank AnalyzerSAP S/4hana FOR Financial Products Subledger | 9/9/2020 | 17/6/2026 | Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system administrator to create incorrect… | |
| Modificada | Media (4.3) | 0.56% | — | SAP S/4 Hana Fiori UI FOR General Ledger Accounting | 12/8/2020 | 17/6/2026 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check. | |
| Modificada | Alta (7.5) | 1.0% | — | Simpleledger Slp-validate | 30/7/2020 | 17/6/2026 | In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group… | |
| Modificada | Alta (7.5) | 1.0% | — | Simpleledger Slpjs | 30/7/2020 | 17/6/2026 | In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as… | |
| Modificada | Alta (8.1) | 0.57% | — | Ledger Live | 2/7/2020 | 17/6/2026 | Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and does not decrease the balance when it is canceled. As a result, users are exposed to basic double… | |
| Modificada | Alta (8.6) | 1.0% | — | Simpleledger Slp-validate | 12/5/2020 | 17/6/2026 | In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in… | |
| Modificada | Alta (8.6) | 0.93% | — | Simpleledger Slpjs | 12/5/2020 | 17/6/2026 | SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is… | |
| Modificada | Media (5.5) | 0.44% | — | Ledger Monero | 6/5/2020 | 17/6/2026 | A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC. | |
| Modificada | Alta (8.6) | 1.6% | — | Simpleledger Electron-cash-slp | 28/4/2020 | 17/6/2026 | Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting authority baton to the wrong SLP address. Sending the mint baton to the wrong address will give another party the ability to issue new… | |
| Modificada | Alta (7.5) | 1.7% | — | Oracle General Ledger | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General… | |
| Modificada | Media (4.3) | 0.74% | — | Banking Services From SAPSAP S/4hana Financial Products Subledger | 14/4/2020 | 17/6/2026 | SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system. | |
| Modificada | Media (6.1) | 1.1% | — | Simpleledger Slpjs | 15/11/2019 | 17/6/2026 | A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. Affected users can upgrade to any version >= 0.21.4. |