Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.49% | — | Golang Crypto | 22/5/2026 | 23/7/2026 | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a… | |
| Modificada | Crítica (9.1) | 0.62% | — | Golang Crypto | 22/5/2026 | 16/9/2026 | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded. | |
| Modificada | Alta (7.5) | 0.62% | — | Golang Crypto | 22/5/2026 | 16/9/2026 | The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication.… | |
| Modificada | Media (6.3) | 0.54% | — | Golang Crypto | 22/5/2026 | 11/9/2026 | When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a… | |
| Analizada | Media (6.5) | 0.28% | — | Golang Crypto | 22/5/2026 | 23/7/2026 | An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection. | |
| Modificada | Media (5.3) | 0.66% | — | Golang Crypto | 22/5/2026 | 18/9/2026 | SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | |
| Aplazada | Media (5.7) | 0.10% | — | NetbsdAINetbsd OpencryptoAI | 18/5/2026 | 14/7/2026 | NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation… | |
| Aplazada | Media (4.1) | 0.15% | — | Sixgates Sixg301xxxAISymcryptoAI | 15/5/2026 | 7/10/2026 | * Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability. | |
| Analizada | Media (6.9) | 0.60% | — | Cross-crypto Cross-implementation | 8/5/2026 | 17/6/2026 | CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7. | |
| Analizada | Media (6.9) | 0.39% | — | Thalesgroup Ercom Cryptobox | 7/5/2026 | 17/6/2026 | Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link. | |
| Pendiente de análisis | Media (4.9) | 0.40% | — | CryptoboxAI | 28/4/2026 | 17/6/2026 | A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request. | |
| Analizada | Media (6.1) | 0.16% | — | Opencryptoki Project Opencryptoki | 16/4/2026 | 17/6/2026 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and trust attacker-controlled BER length fields without validating them against actual buffer… | |
| Analizada | Media (4.8) | 0.14% | — | Cryptomator | 16/4/2026 | 17/6/2026 | Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causing HTTPS URLs with… | |
| Aplazada | Alta (7.5) | 0.35% | — | Accept Cryptocurrencies With PlisioAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a through 2.0.5. | |
| Modificada | Media (6.9) | 0.76% | — | Cryptography.io Cryptography | 8/4/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Adastracrypto Cryptocurrency Donation BOXAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. | |
| Analizada | Media (5.3) | 0.43% | — | Latchset Jwcrypto | 7/4/2026 | 24/7/2026 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output… | |
| Analizada | Alta (7.5) | 0.53% | — | Apple Swift-crypto | 3/4/2026 | 24/7/2026 | A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1. | |
| Analizada | Media (5.9) | 0.26% | — | Leancrypto | 2/4/2026 | 24/7/2026 | The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms. Prior to version 1.7.1, lc_x509_extract_name_segment() casts size_t vlen to uint8_t when storing the Common Name (CN) length. An attacker who crafts a certificate with CN = victim's CN + 256 bytes… | |
| Analizada | Crítica (9.1) | 0.28% | — | ARM Mbed TLSARM Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is… | |
| Analizada | Media (5.1) | 0.27% | — | ARM Mbed TLSARM Tf-psa-crypto | 1/4/2026 | 17/6/2026 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | |
| Analizada | Media (6.7) | 0.15% | — | ARM Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). | |
| Analizada | Alta (7.7) | 0.18% | — | ARM Mbed TLSTrustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). | |
| Analizada | Crítica (9.8) | 0.60% | — | Trustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto | 1/4/2026 | 17/6/2026 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. | |
| Analizada | Baja (1.7) | 0.17% | — | Cryptography.io Cryptography | 31/3/2026 | 17/6/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named… |