Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.44% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree… | |
| Aplazada | Media (5.3) | 0.51% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without per-peer… | |
| Aplazada | Media (6.5) | 0.53% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the… | |
| Aplazada | Crítica (9.3) | 0.32% | — | ZebradAIHalo2 GadgetsAIZcash PrimitivesAIOrchardproject OrchardAI+1 | 17/7/2026 | 17/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying… | |
| Aplazada | Alta (8.7) | 0.54% | — | ZebraAI | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the… | |
| Analizada | Media (5.3) | 0.41% | — | Zfnd Zebra-chainZfnd Zebra-networkZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus… | |
| Analizada | Crítica (9.2) | 0.38% | — | Zfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block can split the… | |
| Analizada | Crítica (9.3) | 0.30% | — | Zfnd Zebra-scriptZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of returning an error, the… | |
| Analizada | Media (6.9) | 0.43% | — | Zfnd Zebra-rpcZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the request body is fully… | |
| Analizada | Crítica (9.2) | 0.46% | — | Zfnd Zebra-chainZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the… | |
| Analizada | Crítica (9.3) | 0.47% | — | Zfnd Zebra-scriptZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes… | |
| Analizada | Media (6.3) | 0.46% | — | Zfnd Zebra-networkZfnd Zebrad | 21/4/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB message size limit.… | |
| Analizada | Alta (7.2) | 0.44% | — | Zfnd Zebra-consensusZfnd Zebrad | 21/4/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and… | |
| Analizada | Alta (8.4) | 0.38% | — | Zfnd ZebraZfnd Zebra-consensus | 31/3/2026 | 24/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner… | |
| Analizada | Crítica (9.2) | 0.93% | — | Zfnd ZebraZfnd Zebra-chain | 31/3/2026 | 24/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that… | |
| Aplazada | Baja (2.4) | 0.52% | — | Zebra ZTC Gk420dAI | 1/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Zebra ZTC GK420d 1.0. This vulnerability affects unknown code of the file /settings of the component Alert Setup Page. The manipulation of the argument Address leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.3) | 0.27% | — | Zebra Zt410 Firmware | 11/10/2023 | 17/6/2026 | A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi… | |
| Modificada | Alta (7.8) | 0.20% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without restriction. | |
| Modificada | Media (5.5) | 0.19% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK. | |
| Modificada | Alta (7.1) | 0.19% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin. | |
| Modificada | Crítica (9.8) | 1.6% | — | Zebra Fx9500 Firmware | 11/5/2021 | 17/6/2026 | An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code execution. NOTE: This vulnerability only… | |
| Modificada | Alta (7.5) | 1.7% | — | Zebra Fx9500 Firmware | 23/3/2020 | 17/6/2026 | Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp. | |
| Modificada | Alta (7.5) | 1.7% | — | Zebra Zt610 FirmwareZebra Zt620 FirmwareZebra Zt510 FirmwareZebra Zt410 Firmware+4 | 20/8/2019 | 17/6/2026 | Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer… | |
| Modificada | Media (6.8) | 7.4% | — | Zebrafeeds | 21/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU ZebraQuagga Routing Software Suite | 15/12/2003 | 16/6/2026 | Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface. |