Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
465 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.62% | 💥 PoC | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have… | |
| Modificada | Media (4) | 0.13% | — | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed… | |
| Modificada | Media (4.7) | 0.18% | — | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service… | |
| Analizada | Media (5.9) | 0.45% | — | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work,… | |
| Analizada | Media (5.5) | 0.20% | — | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the… | |
| Analizada | Media (5.9) | 0.83% | — | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service. Some… | |
| Modificada | Alta (8.8) | 52% | 💥 PoC | Openssl | 27/1/2026 | 7/9/2026 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData… | |
| Modificada | Media (6.1) | 5.1% | 💥 PoC | Openssl | 27/1/2026 | 17/6/2026 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an… | |
| Aplazada | Alta (7.8) | 0.15% | — | Akamai Guardicore Platform AgentAIOpensslAI | 3/12/2025 | 17/6/2026 | The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows… | |
| Aplazada | Baja (2.7) | 0.20% | — | OpensslAI | 22/10/2025 | 17/6/2026 | A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password protected self-signed certificate. | |
| Aplazada | Media (5.9) | 2.0% | — | OpensslAI | 30/9/2025 | 14/7/2026 | Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial… | |
| Aplazada | Media (6.5) | 2.2% | — | OpensslAI | 30/9/2025 | 14/7/2026 | Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker..… | |
| Aplazada | Alta (7.5) | 1.6% | — | OpensslAI | 30/9/2025 | 14/7/2026 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption… | |
| Aplazada | Baja (3.7) | 0.36% | — | OpensslAIGnome Glib-networkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. | |
| Aplazada | Media (4.8) | 0.31% | — | OpensslAIGlib-networking Glib NetworkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read. | |
| Aplazada | Baja (3.4) | 0.14% | — | SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on… | |
| Analizada | Baja (3.3) | 0.20% | — | Sfackler Openssl | 28/7/2025 | 17/9/2026 | The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host. | |
| Aplazada | Media (6.7) | 0.17% | — | OpensslAI | 21/7/2025 | 17/6/2026 | A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges. | |
| Aplazada | Media (5.3) | 0.43% | — | OpensslAI | 16/6/2025 | 17/6/2026 | OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce,… | |
| Analizada | Media (6.5) | 0.36% | — | Openssl | 22/5/2025 | 17/6/2026 | Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use. A copy & paste error during minor… | |
| Aplazada | Alta (7.5) | 0.29% | — | ActualizerAIOpensslAIDebianAI | 13/5/2025 | 17/6/2026 | Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer users building a full… | |
| Analizada | Alta (7) | 0.22% | — | Conda-forge MiniforgeConda-forge Openssl-feedstock | 13/5/2025 | 17/6/2026 | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the… | |
| Analizada | Media (5.7) | 0.19% | — | JrubyJruby-openssl | 7/5/2025 | 17/6/2026 | JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not… | |
| Aplazada | Baja (2.5) | 0.17% | — | Nvidia NvcontainerAIOpensslAI | 22/4/2025 | 17/6/2026 | NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | |
| Aplazada | Baja (3.7) | 0.51% | — | OpensslAI | 8/4/2025 | 30/6/2026 | A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string. |