Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.49% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory leak vulnerability was identified in the… | |
| Analizada | Alta (8.9) | 1.1% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a heap buffer overflow vulnerability in CryptoLib's… | |
| Aplazada | Crítica (9.3) | 9.6% | 💥 PoC | Xml-cryptoAI | 14/3/2025 | 17/6/2026 | xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication or authorization mechanisms in systems that rely on xml-crypto for verifying signed XML documents. The vulnerability allows… | |
| Aplazada | Crítica (9.3) | 9.1% | 💥 PoC | Xml-cryptoAI | 14/3/2025 | 17/6/2026 | xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication or authorization mechanisms in systems that rely on xml-crypto for verifying signed XML documents. The vulnerability allows… | |
| Analizada | Media (6.5) | 0.38% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests. | |
| Analizada | Baja (3.7) | 0.26% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations. | |
| Analizada | Media (6.5) | 0.44% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | |
| Analizada | Alta (7.5) | 0.18% | — | Intel Integrated Performance Primitives Cryptography | 14/2/2025 | 17/6/2026 | Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (7.5) | 1.4% | — | Microsoft Go-crypto-winnativeAI | 12/2/2025 | 17/6/2026 | go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak every time. Commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 contains a fix for… | |
| Aplazada | Media (4.3) | 0.48% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 7/1/2025 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK… | |
| Aplazada | Media (6.1) | 0.35% | — | Financial Stocks Crypto Market Data PluginAI | 7/1/2025 | 17/6/2026 | The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'e' parameter in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.9) | 0.41% | — | Falselight Cryptocurrency Price WidgetAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Cryptocurrency Price Widget cryptocurrency-price-widget allows Stored XSS.This issue affects Cryptocurrency Price Widget: from n/a through <= 1.2.3. | |
| Modificada | Crítica (9.8) | 0.93% | — | Coolplugins Cryptocurrency Widgets | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2. | |
| Aplazada | Media (5.3) | 0.44% | — | Depay Web3 Crypto PaymentsAI | 12/12/2024 | 17/6/2026 | The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/depay/wc/debug REST API endpoint in all versions up to, and including, 2.12.17. This makes it possible for unauthenticated attackers to retrieve debug… | |
| Aplazada | Crítica (9.1) | 3.2% | 💥 PoC | Golang X CryptoAI | 12/12/2024 | 17/6/2026 | Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to… | |
| Modificada | Crítica (9.8) | 0.66% | — | Coolplugins Cryptocurrency Widgets FOR Elementor | 30/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <=… | |
| Analizada | Media (6.1) | 0.59% | — | Hedge3 Crypto AND Defi Widgets | 21/11/2024 | 17/6/2026 | The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Binance BTC Crypto AND NftsAI | 14/11/2024 | 17/6/2026 | A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint. | |
| Modificada | Alta (8.8) | 0.29% | — | Odude Crypto Tool | 29/10/2024 | 17/6/2026 | The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an… | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Odude Crypto Tool | 29/10/2024 | 17/6/2026 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in… | |
| Modificada | Crítica (9.8) | 1.1% | — | Odude Crypto Tool | 29/10/2024 | 17/6/2026 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the… | |
| Aplazada | Alta (8.5) | 0.20% | — | Openssl LibcryptoAIFlashfxpAI | 17/10/2024 | 17/6/2026 | A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.49% | — | Nasa Cryptolib | 27/9/2024 | 17/6/2026 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c). | |
| Modificada | Alta (7.5) | 0.52% | — | Nasa Cryptolib | 27/9/2024 | 17/6/2026 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c). | |
| Modificada | Alta (7.5) | 0.53% | — | Nasa Cryptolib | 27/9/2024 | 17/6/2026 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c). |