Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.29% | — | Jahlives Openssl EncryptAI | 27/8/2026 | 23/9/2026 | openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password verification occurs. | |
| Aplazada | Alta (8.6) | 0.16% | — | Jahlives Openssl EncryptAI | 27/8/2026 | 23/9/2026 | openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems. | |
| Aplazada | Alta (8.2) | 0.51% | — | Djust Phoenix LiveviewAI | 25/8/2026 | 9/9/2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, but returns without… | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Media (4.3) | 0.38% | — | OlivetinAI | 21/8/2026 | 9/9/2026 | OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prior to commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d, a special case allows any… | |
| Analizada | Crítica (9.3) | 23% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/8/2026 | 10/9/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | |
| Analizada | Alta (7.3) | 0.16% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful… | |
| Analizada | Media (6.8) | 0.40% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery… | |
| Analizada | Alta (8.7) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform.… | |
| Analizada | Crítica (9.3) | 0.40% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection. | |
| Analizada | Crítica (9.3) | 0.56% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the… | |
| Analizada | Crítica (9.3) | 0.75% | — | Jahlives Openssl Encrypt | 17/8/2026 | 28/8/2026 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands. | |
| Analizada | Crítica (9.3) | 0.56% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary… | |
| Analizada | Crítica (9.3) | 0.68% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. | |
| Analizada | Crítica (9.3) | 0.66% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the… | |
| Analizada | Alta (8.7) | 0.45% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs. | |
| Analizada | Alta (8.7) | 0.51% | — | Jahlives Openssl Encrypt | 17/8/2026 | 31/8/2026 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication. | |
| Analizada | Alta (8.7) | 0.52% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data. | |
| Analizada | Crítica (9.3) | 0.21% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and… | |
| Analizada | Crítica (9.3) | 0.35% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. | |
| Analizada | Alta (8.7) | 0.27% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy… | |
| Analizada | Media (6.3) | 0.30% | — | Jahlives Openssl Encrypt | 17/8/2026 | 31/8/2026 | openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could… |