Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.43% | — | Consensys Gnark-crypto | 6/9/2024 | 17/6/2026 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with commitments. Notably, PLONK proofs are not affected. The… | |
| Analizada | Media (6.2) | 0.19% | — | Consensys Gnark-crypto | 6/9/2024 | 17/6/2026 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark uses the commitments for optimized non-native multiplication,… | |
| Analizada | Media (6.1) | 0.31% | — | Coolplugins Cryptocurrency Widgets | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Reflected XSS.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.8.0. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Integrated Performance Primitives CryptographyIntel Oneapi Base Toolkit | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.1) | 0.15% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 31/7/2024 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (5.4) | 0.28% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 18/7/2024 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value… | |
| Analizada | Media (4.7) | 0.15% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 22/5/2024 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Aplazada | Media (5.5) | 0.19% | — | Matrix-sdk-cryptoAI | 14/5/2024 | 17/6/2026 | The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Cryptopp Crypto++AI | 14/5/2024 | 17/6/2026 | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges. | |
| Aplazada | Crítica (10) | 0.83% | 💥 PoC | Xml-cryptoAI | 2/5/2024 | 17/6/2026 | xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the… | |
| Aplazada | Alta (8.2) | 0.30% | — | QemuAIQemu Virtio GPUAIQemu Virtio Serial BUSAIQemu Virtio CryptoAI | 9/4/2024 | 17/6/2026 | A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial… | |
| Modificada | Alta (8.2) | 0.85% | — | ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora | 29/3/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. | |
| Aplazada | Media (6.5) | 0.33% | — | Currencyratetoday Crypto Converter WidgetAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.4. | |
| Analizada | Alta (7.5) | 0.64% | — | IBM Common Cryptographic Architecture | 26/3/2024 | 17/6/2026 | IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602. | |
| Analizada | Baja (3.7) | 0.45% | — | IBM Common Cryptographic Architecture | 26/3/2024 | 17/6/2026 | Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676. | |
| Analizada | Media (6.8) | 0.98% | — | Latchset JwcryptoDebian Linux | 21/3/2024 | 17/6/2026 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version… | |
| Modificada | Media (4.7) | 0.40% | — | Coolplugins Cryptocurrency Widgets | 13/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.8. | |
| Aplazada | Media (5.9) | 0.67% | — | Golang Crypto/tlsAI | 5/3/2024 | 17/6/2026 | Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not… | |
| Analizada | Alta (7.5) | 0.83% | — | Cryptography.io Cryptography | 21/2/2024 | 17/6/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an… | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.17% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.8% | 💥 PoC | Miniorange Web3 - Crypto Wallet Login & NFT Token Gating | 12/2/2024 | 17/6/2026 | The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an… | |
| Modificada | Media (5.3) | 0.88% | — | Latchset JwcryptoFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux FOR ARM 64+2 | 12/2/2024 | 17/6/2026 | A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack. | |
| Analizada | Alta (7.5) | 0.95% | — | Coolplugins Cryptocurrency Widgets | 5/2/2024 | 17/6/2026 | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |