Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—Wolfssl28/1/202017/6/2026
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.
ModificadaMedia (5.3)0.95%—Wolfssl25/12/201917/6/2026
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.
ModificadaAlta (7.5)0.90%—Wolfssl25/12/201917/6/2026
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
ModificadaMedia (5.3)0.95%—Wolfssl25/12/201917/6/2026
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
ModificadaMedia (5.3)1.8%—Wolfssl11/12/201917/6/2026
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c fixes two bits of the generated nonces.
ModificadaAlta (7.5)0.88%—Wolfssl21/11/201917/6/2026
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
ModificadaAlta (7.5)0.81%—Wolfssl21/11/201917/6/2026
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
ModificadaAlta (7.5)0.73%—Wolfssl21/11/201917/6/2026
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
ModificadaAlta (7.5)2.0%—Wolfssl9/11/201917/6/2026
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled.…
ModificadaMedia (4.7)0.36%—Wolfssl3/10/201917/6/2026
wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the duration of signature operations, to infer information about the nonces used and…
ModificadaCrítica (9.8)1.2%—Wolfssl24/9/201917/6/2026
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c.
ModificadaCrítica (9.8)1.0%—Wolfssl26/8/201917/6/2026
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.
ModificadaCrítica (9.8)2.9%—Wolfvision Cynap5/7/201917/6/2026
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.
ModificadaCrítica (9.8)9.2%—Wolfssl23/5/201917/6/2026
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions…
ModificadaMedia (4.8)1.0%—Wolfcms Wolf CMS25/4/201917/6/2026
WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
ModificadaMedia (4.8)1.0%—Wolfcms Wolf CMS25/4/201917/6/2026
WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
ModificadaMedia (6.1)0.86%—Wolfcms Wolf CMS30/3/201917/6/2026
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.
ModificadaCrítica (9.8)2.6%—Wolfssl16/1/201917/6/2026
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
ModificadaMedia (5.9)1.6%—Wolfssl3/1/201917/6/2026
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
ModificadaAlta (7.5)1.3%—Lwolf Loading Docs12/9/201817/6/2026
Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs.
ModificadaMedia (4.8)0.66%—Wolfcms Wolf CMS25/8/201817/6/2026
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
ModificadaMedia (4.8)0.67%—Wolfcms Wolf CMS10/8/201817/6/2026
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
ModificadaCrítica (9.8)1.6%—Wolfsight CMS12/7/201817/6/2026
WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
ModificadaMedia (4.7)0.39%—Wolfssl15/6/201817/6/2026
wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
ModificadaAlta (7.5)8.7%💥 ExploitWerewolf Online Project Werewolf Online26/5/201817/6/2026
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.