Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
465 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 2.5% | — | OpensslAI | 11/2/2025 | 17/6/2026 | Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections using raw public keys may be vulnerable… | |
| Aplazada | Media (6.3) | 0.68% | — | Rust-openssl OpensslAI | 3/2/2025 | 17/6/2026 | rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's lifetime is shorter than the `client`… | |
| Aplazada | Alta (8.5) | 0.81% | — | Flexnet PublisherAIOpensslAI | 30/1/2025 | 17/6/2026 | A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file… | |
| Aplazada | Media (4.1) | 0.61% | 💥 PoC | OpensslAI | 20/1/2025 | 17/6/2026 | Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local… | |
| Aplazada | Alta (8.2) | 0.28% | 💥 PoC | ROS 2AIOpensslAI | 9/1/2025 | 17/6/2026 | An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant… | |
| Aplazada | Alta (8.2) | 0.34% | — | ROS 2AIOpensslAI | 9/1/2025 | 17/6/2026 | An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant… | |
| Aplazada | Alta (8.2) | 0.34% | — | OpensslAIROS 2AI | 9/1/2025 | 17/6/2026 | An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant… | |
| Aplazada | Alta (8.2) | 0.46% | — | Intel QAT Engine FOR OpensslAI | 13/11/2024 | 17/6/2026 | Insufficient control flow management in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access. | |
| Aplazada | Alta (8.2) | 0.52% | — | Intel QAT Engine FOR OpensslAIOpensslAI | 13/11/2024 | 17/6/2026 | Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access. | |
| Aplazada | Alta (8.2) | 0.43% | — | Intel QAT Engine FOR OpensslAI | 13/11/2024 | 17/6/2026 | Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access. | |
| Aplazada | Alta (7.5) | 2.9% | — | OpensslAI | 13/11/2024 | 17/6/2026 | Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only… | |
| Aplazada | Alta (8.5) | 0.20% | — | Openssl LibcryptoAIFlashfxpAI | 17/10/2024 | 17/6/2026 | A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has been disclosed… | |
| Aplazada | Media (4.3) | 5.8% | — | OpensslAI | 16/10/2024 | 17/6/2026 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, however, in all the… | |
| Aplazada | Media (6.5) | 0.30% | — | Golang Fips OpensslAI | 1/10/2024 | 21/9/2026 | A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to… | |
| Aplazada | Alta (7.4) | 1.3% | — | Nodejs Node.jsAIOpensslAI | 7/9/2024 | 17/6/2026 | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key. | |
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Aplazada | Media (6.5) | 0.74% | — | CpythonAIOpensslAI | 27/6/2024 | 31/7/2026 | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely… | |
| Aplazada | Crítica (9.1) | 5.6% | 💥 PoC | OpensslAI | 27/6/2024 | 17/6/2026 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected application beahviour or a crash. In… | |
| Aplazada | Alta (8.2) | 0.45% | — | Oqs-providerAIOpensslAIOpenquantumsafe LiboqsAI | 17/6/2024 | 17/6/2026 | oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid… | |
| Aplazada | Media (5.3) | 1.1% | — | OpensslAI | 16/5/2024 | 17/6/2026 | Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been… | |
| Aplazada | Media (5.9) | 0.52% | — | Perl Crypt-openssl-rsaAI | 25/4/2024 | 17/6/2026 | A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the… | |
| Aplazada | Media (5.9) | 2.3% | — | OpensslAI | 25/4/2024 | 17/6/2026 | Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial… | |
| Aplazada | Media (5.9) | 52% | — | OpensslAI | 8/4/2024 | 17/6/2026 | Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the… | |
| Aplazada | Media (5.9) | 0.41% | — | Rust-opensslAI | 4/4/2024 | 17/6/2026 | A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects… | |
| Aplazada | Alta (7.8) | 0.23% | — | Rapid7 Minerva ArmorAIOpensslAI | 3/4/2024 | 17/6/2026 | Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege. The vulnerability is caused by the product's implementation of OpenSSL's`OPENSSLDIR` parameter where it is set to a path… |