Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.74%—Openzeppelin ContractsOpenzeppelin Contracts-upgradable10/8/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20…
ModificadaMedia (5.9)0.37%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to construct merkle trees that allow forging a…
ModificadaMedia (5.3)0.60%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable7/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in…
ModificadaMedia (5.3)0.81%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable17/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert…
ModificadaAlta (8.8)0.58%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if…
ModificadaMedia (6.5)0.71%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable3/3/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by…
ModificadaMedia (5.3)0.22%—Openzeppelin Contracts3/2/202317/6/2026
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using `is_valid_eth_signature` from the account…
ModificadaMedia (5.4)1.1%—Apache Zeppelin16/12/202217/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.
ModificadaMedia (6.5)1.6%—Apache Zeppelin16/12/202217/6/2026
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
ModificadaMedia (5.6)0.53%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable4/11/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an…
ModificadaMedia (6.5)0.42%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable15/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditional 65 byte signature format. This is only an issue for the…
ModificadaMedia (5.3)0.58%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned accounts (EOAs) as cross chain calls, even though they are not started on L1.…
ModificadaMedia (5.3)0.78%—Openzeppelin ContractsOpenzeppelin Contracts UpgradeableOpenzeppelin-ethOpenzeppelin-solidity1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are…
ModificadaAlta (7.5)0.77%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as a percentage of the voting token's total supply. In affected instances, when a proposal is passed to…
ModificadaAlta (7.5)0.49%—Openzeppelin Contracts22/7/202217/6/2026
OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignatureNow` is not expected to revert. However, an incorrect assumption about Solidity 0.8's `abi.decode` allows some cases to revert, given a…
ModificadaAlta (7.5)0.77%—Openzeppelin Contracts22/7/202217/6/2026
OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of returning `false`. `ERC165Checker.supportsInterface` is designed to always successfully return a boolean, and under no circumstance revert. However, an incorrect…
ModificadaMedia (6.5)1.5%—Openzeppelin Contracts15/7/202217/6/2026
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of…
ModificadaAlta (7.5)1.2%—Openzeppelin4/2/202217/6/2026
In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has finished running it can never be re-executed. However, an exception put in place…
ModificadaCrítica (9.8)1.5%—Openzeppelin Contracts12/11/202117/6/2026
OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and…
ModificadaMedia (6.1)3.2%—Apache Zeppelin2/9/202117/6/2026
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apache Zeppelin Apache Zeppelin versions prior to 0.9.0.
ModificadaAlta (7.5)3.3%—Apache Zeppelin2/9/202117/6/2026
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
ModificadaCrítica (9.8)5.7%—Apache Zeppelin2/9/202117/6/2026
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
ModificadaCrítica (9.8)1.6%—Openzeppelin Contracts27/8/202117/6/2026
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not…
ModificadaCrítica (9.8)1.6%—Openzeppelin Contracts27/8/202117/6/2026
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not…
ModificadaMedia (6.1)6.0%—Apache Zeppelin23/4/201917/6/2026
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".