Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

355 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.49%—Vyperlang Vyper4/9/202317/6/2026
Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compiler evaluates the arguments from right to left instead of left to right. `unsafe_add, unsafe_sub, unsafe_mul, unsafe_div, pow_mod256, |, &, ^ (bitwise operators), bitwise_or (deprecated), bitwise_and…
ModificadaCrítica (9.8)2.6%—Perl22/8/202317/6/2026
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
ModificadaCrítica (9.1)0.82%—Vyperlang Vyper7/8/202317/6/2026
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0, named re-entrancy locks are allocated incorrectly. Each function using a named re-entrancy lock gets a unique lock regardless of the key, allowing cross-function re-entrancy in contracts compiled…
ModificadaMedia (5.3)0.57%—Vyperlang Vyper25/7/202317/6/2026
Vyper is a Pythonic programming language that targets the Ethereum Virtual Machine (EVM). Prior to version 0.3.10, the ecrecover precompile does not fill the output buffer if the signature does not verify. However, the ecrecover builtin will still return whatever is at memory location 0. This means that the if the…
ModificadaMedia (5.3)0.55%—Vyperlang Vyper19/5/202317/6/2026
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In contracts with more than one regular nonpayable function, it is possible to send funds to the default function, even if the default function is marked `nonpayable`. This applies to contracts compiled with vyper versions prior to 0.3.8.…
ModificadaAlta (7.5)0.73%—Vyperlang Vyper11/5/202317/6/2026
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, internal calls with default arguments are compiled incorrectly. Depending on the number of arguments provided in the call, the defaults are added not right-to-left, but left-to-right. If the types are incompatible,…
ModificadaAlta (7.5)0.91%—Vyperlang Vyper11/5/202317/6/2026
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing overflow check for loop variables, by assigning the iterator of a loop to a variable, it is possible to overflow the type of the latter. The issue seems to happen only in loops of type `for i in…
ModificadaCrítica (9.1)1.2%—Vyperlang Vyper11/5/202317/6/2026
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, the length word of a dynarray is written before the data, which can result in out-of-bounds array access in the case where the dynarray is on both the lhs and rhs of an assignment. The issue can cause…
ModificadaAlta (7.5)0.70%—Vyperlang Vyper8/5/202317/6/2026
Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8.
ModificadaAlta (8.1)1.7%—Http\ \Perl29/4/202317/6/2026
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
ModificadaAlta (8.1)1.5%—Cpanpm Project CpanpmPerl29/4/202317/6/2026
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
ModificadaAlta (7.5)0.88%—Vyperlang Vyper24/4/202317/6/2026
Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.1 through 0.3.7, the Vyper compiler generates the wrong bytecode. Any contract that uses the `raw_call` with `revert_on_failure=False` and `max_outsize=0` receives the wrong response from `raw_call`. Depending on the memory…
ModificadaAlta (7.5)0.85%—Hyperledger Fabric12/11/202217/6/2026
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabric with Raft prevents exploitation via a locking mechanism and a check for names that already exist.
ModificadaAlta (8.8)1.2%—Strawberryperl30/8/202217/6/2026
Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaMedia (5.4)0.61%—Auto-hyperlink Urls Project Auto-hyperlink Urls22/8/202217/6/2026
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.
ModificadaMedia (5.3)1.1%—Hyperledger Fabric18/8/202217/6/2026
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the…
ModificadaAlta (7.5)2.1%—Hyperledger Fabric7/7/202217/6/2026
Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the orderer node. A fix has been added in commit 0f1835949 which checks for missing consensus messages and returns an error to the consensus…
ModificadaAlta (7.5)1.3%—Vyperlang Vyper9/6/202217/6/2026
Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling an external contract with no return value, the contract address (including side effects) could be evaluated twice. This may result in incorrect outcomes for contracts. This issue has been addressed…
ModificadaCrítica (9.8)1.4%—Vyperlang Vyper13/4/202217/6/2026
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<iface>.returns_int128()` is not validated to fall within the bounds of `int128`. This issue can result in a misinterpretation of the integer value and lead to incorrect behavior. As of v0.3.0,…
ModificadaCrítica (9.8)0.99%—Vyperlang Vyper13/4/202217/6/2026
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a JSON interface which returns `bytes` generates bytecode which does not clamp bytes length, potentially resulting in a buffer overrun. Users…
ModificadaAlta (7.5)1.0%—Vyperlang Vyper4/4/202217/6/2026
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty nonzero bytes, two bytestrings can compare to equal if one ends with `"\x00"`…
ModificadaAlta (7.8)0.86%—Comprehensive Perl Archive NetworkFedoraproject Fedora13/12/202117/6/2026
CPAN 2.28 allows Signature Verification Bypass.
ModificadaAlta (7.2)6.7%💥 ExploitG Auto-hyperlink Project G Auto-hyperlink8/11/202117/6/2026
The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection
ModificadaAlta (8.8)1.1%—Vyperlang Vyper6/10/202117/6/2026
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack. This issue has been resolved in version 0.3.0.
ModificadaMedia (4.3)0.80%—Vyperlang Vyper5/10/202117/6/2026
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0.
Orbitaley — Vulnerabilidades