Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.13% | — | Wolfssl | 22/11/2025 | 17/6/2026 | With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest. | |
| Analizada | Baja (1) | 0.29% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now… | |
| Analizada | Media (6.3) | 0.43% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and… | |
| Analizada | Baja (2.1) | 0.15% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously could respond as ECDSA… | |
| Analizada | Baja (2.3) | 0.42% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions. | |
| Analizada | Baja (2.3) | 0.26% | — | Wolfssl | 21/11/2025 | 17/6/2026 | The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder | |
| Analizada | Baja (2.1) | 0.32% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application. | |
| Analizada | Media (6.3) | 0.21% | — | Wolfssl | 21/11/2025 | 17/6/2026 | With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of… | |
| Analizada | Crítica (9.8) | 0.64% | — | Axeltechnology Wolf1ms FirmwareAxeltechnology Wolf2ms Firmware | 19/11/2025 | 17/6/2026 | The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system… | |
| Analizada | Crítica (9.4) | 0.43% | — | Wolfssh | 21/10/2025 | 17/6/2026 | Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials. | |
| Analizada | Baja (1.8) | 0.37% | — | Wolfssh | 21/10/2025 | 17/6/2026 | Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed. | |
| Aplazada | Alta (7.3) | 0.18% | — | LibrewolfAI | 19/10/2025 | 17/6/2026 | A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component Installer. Such manipulation leads to uncontrolled search path. The attack must be carried out locally. Attacks of this nature are highly complex. The… | |
| Aplazada | Baja (1) | 0.14% | — | Wolfssl WolftpmAI | 4/8/2025 | 17/6/2026 | Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if the default `MAX_RSA_KEY_BITS=2048` is used. If your TPM 2.0 module supports RSA key sizes larger than 2048 bit and your applications supports creating or importing an RSA private or public key larger than 2048 bits and… | |
| Analizada | Media (5.6) | 0.19% | — | Wolfssl | 18/7/2025 | 17/6/2026 | In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature. While the… | |
| Aplazada | Crítica (9.2) | 0.24% | — | WolfsslAI | 18/7/2025 | 17/6/2026 | A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the… | |
| Analizada | Alta (7) | 0.40% | — | Wolfssl | 18/7/2025 | 17/6/2026 | In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes()… | |
| Analizada | Media (6.8) | 0.31% | — | Wolfbox Level 2 EV Charger Firmware | 6/6/2025 | 17/6/2026 | WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 0.38% | — | Wolfbox Level 2 EV Charger Firmware | 6/6/2025 | 17/6/2026 | WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.21% | — | Wolfbox Level 2 EV Charger Firmware | 6/6/2025 | 17/6/2026 | WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authentication is not required to exploit this vulnerability. The… | |
| Analizada | Alta (8) | 0.45% | — | Wolfbox Level 2 EV Charger Firmware | 6/6/2025 | 17/6/2026 | WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger. Although authentication is required to exploit this vulnerability, the existing… | |
| Analizada | Alta (8) | 0.41% | — | Wolfbox Level 2 EV Charger Firmware | 6/6/2025 | 17/6/2026 | WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatons of WOLFBOX Level 2 EV Charger devices. Authentication is required to exploit this vulnerability. The… | |
| Analizada | Media (4.8) | 0.36% | — | Wolfnettech Wolfnet IDX FOR Wordpress | 15/5/2025 | 17/6/2026 | The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration Testing TrackingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration TestingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Media (6.5) | 0.25% | — | Wolfgang Include Mastodon FeedAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: from n/a through <= 1.9.9. |