Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Nasatheme Nasa CoreAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Core nasa-core allows Reflected XSS.This issue affects Nasa Core: from n/a through <= 6.4.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Nasatheme Nasa CoreAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Core nasa-core allows Stored XSS.This issue affects Nasa Core: from n/a through < 6.4.1. | |
| Aplazada | Alta (8.1) | 0.78% | — | Nasatheme Nasa CoreAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclusion.This issue affects Nasa Core: from n/a through <= 6.3.2. | |
| Modificada | Alta (8.8) | 0.81% | 💥 PoC | Nasatheme Nasa Core | 16/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclusion.This issue affects Nasa Core: from n/a through < 6.4.4. | |
| Analizada | Media (4.2) | 0.35% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. | |
| Analizada | Crítica (9.9) | 0.60% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle. | |
| Analizada | Crítica (9.9) | 0.50% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS). | |
| Analizada | Alta (8.8) | 0.53% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. | |
| Analizada | Crítica (9.3) | 0.66% | — | Nasa Cryptolib | 1/4/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In 1.3.3 and earlier, a heap buffer overflow vulnerability persists in the… | |
| Analizada | Alta (7.5) | 0.48% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service. | |
| Analizada | Crítica (9.8) | 0.51% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform. | |
| Analizada | Alta (7.5) | 0.48% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module. | |
| Analizada | Alta (7.5) | 0.60% | — | Nasa Core Flight System | 25/3/2025 | 17/6/2026 | NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system. | |
| Analizada | Crítica (9.8) | 1.8% | — | Nasa Fprime | 25/3/2025 | 17/6/2026 | A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands. | |
| Analizada | Media (6.1) | 0.29% | — | Nasa Fprime | 25/3/2025 | 17/6/2026 | NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |
| Analizada | Crítica (9.8) | 0.79% | — | Nasa Fprime | 25/3/2025 | 17/6/2026 | A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file. | |
| Analizada | Crítica (9.1) | 2.6% | 💥 PoC | Nasa Cryptolib | 25/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in the… | |
| Analizada | Alta (8.9) | 0.72% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability was identified in the `Crypto_TC_Prep_AAD`… | |
| Analizada | Alta (8.9) | 1.1% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer underflow in the… | |
| Analizada | Alta (8.9) | 0.74% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability was identified in the… | |
| Analizada | Media (5.5) | 0.49% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory leak vulnerability was identified in the… | |
| Analizada | Alta (8.9) | 1.1% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a heap buffer overflow vulnerability in CryptoLib's… | |
| Aplazada | Crítica (9.2) | 0.44% | — | Nasa Ion-dtnAI | 5/12/2024 | 17/6/2026 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when a bundle with a Destination Endpoint ID (EID) set to dtn:none is received. This causes the node to become unresponsive to… | |
| Aplazada | Crítica (9.2) | 0.44% | — | Nasa ION DTNAI | 5/12/2024 | 17/6/2026 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (SSP) in their… | |
| Modificada | Alta (7.5) | 0.49% | — | Nasa Cryptolib | 27/9/2024 | 17/6/2026 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c). |