Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.49% | — | Openzeppelin Contracts | 22/7/2022 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignatureNow` is not expected to revert. However, an incorrect assumption about Solidity 0.8's `abi.decode` allows some cases to revert, given a… | |
| Modificada | Alta (7.5) | 0.77% | — | Openzeppelin Contracts | 22/7/2022 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of returning `false`. `ERC165Checker.supportsInterface` is designed to always successfully return a boolean, and under no circumstance revert. However, an incorrect… | |
| Modificada | Media (6.5) | 1.5% | — | Openzeppelin Contracts | 15/7/2022 | 17/6/2026 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of… | |
| Modificada | Alta (7.5) | 1.2% | — | Openzeppelin | 4/2/2022 | 17/6/2026 | In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has finished running it can never be re-executed. However, an exception put in place… | |
| Modificada | Crítica (9.8) | 1.5% | — | Openzeppelin Contracts | 12/11/2021 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and… | |
| Modificada | Crítica (9.8) | 1.6% | — | Openzeppelin Contracts | 27/8/2021 | 17/6/2026 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not… | |
| Modificada | Crítica (9.8) | 1.6% | — | Openzeppelin Contracts | 27/8/2021 | 17/6/2026 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not… | |
| Modificada | Alta (7.5) | 2.1% | — | Openzfs | 12/2/2021 | 16/6/2026 | An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied. | |
| Modificada | Media (4.7) | 0.45% | — | Openzaak Open Zaak | 18/12/2020 | 17/6/2026 | Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case management. In Open Zaak before version 1.3.3 the Cross-Origin-Resource-Sharing policy in Open Zaak is currently wide open - every client is allowed. This allows evil.com to run scripts that perform AJAX… | |
| Modificada | Alta (7.8) | 0.46% | — | Openzfs | 27/8/2020 | 17/6/2026 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777. | |
| Modificada | Alta (7.8) | 0.48% | — | Openzfs | 27/8/2020 | 17/6/2026 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. |