Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.35% | — | Openpgpjs | 29/8/2023 | 17/6/2026 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typically contain a "Hash: ..." header declaring the hash algorithm used to compute the… | |
| Modificada | Media (6.5) | 0.70% | — | Pgpool-ii | 30/1/2023 | 17/6/2026 | Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series,… | |
| Modificada | Alta (8.8) | 0.67% | — | Yubico Ykneo-openpgp | 30/3/2022 | 17/6/2026 | Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated. | |
| Modificada | Media (4.9) | 0.91% | — | SAP Process Integration (pgp Module - Business-to-business ADD ON) | 10/11/2020 | 17/6/2026 | SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information Disclosure. | |
| Modificada | Media (5.9) | 1.5% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key. | |
| Modificada | Alta (7.5) | 1.6% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. | |
| Modificada | Alta (7.5) | 2.0% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature. | |
| Modificada | Media (5.9) | 1.7% | — | Gpg-pgp Project Gpg-pgp | 16/5/2019 | 17/6/2026 | The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it does not verify the validity of the… | |
| Modificada | Crítica (9.8) | 1.7% | — | Pgpooladmin | 9/1/2019 | 17/6/2026 | PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.9% | — | Openpgpjs | 25/7/2017 | 17/6/2026 | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message. | |
| Modificada | Alta (7.5) | 1.8% | — | Fedoraproject FedoraPgpdump Project Pgpdump | 26/5/2016 | 17/6/2026 | The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string. | |
| Modificada | Alta (9) | 8.1% | — | Symantec Encryption Management ServerSymantec PGP Universal Server | 1/2/2015 | 17/6/2026 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action. | |
| Modificada | Media (5) | 1.1% | — | Symantec Encryption Management ServerSymantec PGP Universal Server | 1/2/2015 | 17/6/2026 | The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header. | |
| Modificada | Media (5) | 1.1% | — | Symantec PGP DesktopSymantec Encryption Desktop | 22/8/2014 | 17/6/2026 | Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size. | |
| Modificada | Media (4.3) | 0.20% | — | Symantec Encryption DesktopSymantec PGP Desktop | 21/6/2014 | 17/6/2026 | Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors. | |
| Modificada | Baja (2.6) | 0.72% | — | Symantec PGP DesktopSymantec Encryption Desktop | 23/4/2014 | 17/6/2026 | Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate. | |
| Modificada | Baja (2.6) | 0.72% | — | Symantec Encryption DesktopSymantec PGP Desktop | 23/4/2014 | 17/6/2026 | Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate. | |
| Modificada | Media (6.8) | 0.30% | — | Symantec Encryption DesktopSymantec PGP Desktop | 5/8/2013 | 16/6/2026 | Unquoted Windows search path vulnerability in RDDService in Symantec PGP Desktop 10.0.x through 10.2.x and Symantec Encryption Desktop 10.3.0 before MP3 allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory. | |
| Modificada | Media (4.3) | 0.89% | — | Symantec Encryption Management ServerSymantec PGP Universal Server | 31/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment. | |
| Modificada | Media (4.4) | 0.62% | — | Symantec PGP DesktopSymantec Encryption Desktop | 18/2/2013 | 16/6/2026 | Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application. | |
| Modificada | Media (6.9) | 0.26% | — | Symantec Encryption DesktopSymantec PGP Desktop | 18/2/2013 | 16/6/2026 | Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a crafted application. | |
| Modificada | Baja (2.9) | 0.63% | — | Symantec PGP Universal Server | 4/9/2012 | 16/6/2026 | Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session. | |
| Modificada | Media (4.3) | 1.6% | — | PGP Desktop FOR WindowsPGP Desktop FOR MAC | 22/11/2010 | 16/6/2026 | PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" functionality for multi-packet OpenPGP messages that represent multi-message input, which allows remote attackers to spoof signed data by concatenating an additional message to the… | |
| Modificada | Alta (9.3) | 4.2% | — | PGP Desktop | 15/9/2010 | 16/6/2026 | Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tsp.dll or tvttsp.dll that is located in the same folder as a… | |
| Modificada | Alta (7.2) | 0.42% | — | PGP Desktop | 15/4/2009 | 16/6/2026 | PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys. |