Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Wolfssl | 28/1/2020 | 17/6/2026 | The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read. | |
| Modificada | Media (5.3) | 0.95% | — | Wolfssl | 25/12/2019 | 17/6/2026 | An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce. | |
| Modificada | Alta (7.5) | 0.90% | — | Wolfssl | 25/12/2019 | 17/6/2026 | wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. | |
| Modificada | Media (5.3) | 0.95% | — | Wolfssl | 25/12/2019 | 17/6/2026 | In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks. | |
| Modificada | Media (5.3) | 1.8% | — | Wolfssl | 11/12/2019 | 17/6/2026 | wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c fixes two bits of the generated nonces. | |
| Modificada | Alta (7.5) | 0.88% | — | Wolfssl | 21/11/2019 | 17/6/2026 | wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. | |
| Modificada | Alta (7.5) | 0.81% | — | Wolfssl | 21/11/2019 | 17/6/2026 | wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. | |
| Modificada | Alta (7.5) | 0.73% | — | Wolfssl | 21/11/2019 | 17/6/2026 | wolfssl before 3.2.0 does not properly issue certificates for a server's hostname. | |
| Modificada | Alta (7.5) | 2.0% | — | Wolfssl | 9/11/2019 | 17/6/2026 | In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled.… | |
| Modificada | Media (4.7) | 0.36% | — | Wolfssl | 3/10/2019 | 17/6/2026 | wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the duration of signature operations, to infer information about the nonces used and… | |
| Modificada | Crítica (9.8) | 1.2% | — | Wolfssl | 24/9/2019 | 17/6/2026 | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c. | |
| Modificada | Crítica (9.8) | 1.0% | — | Wolfssl | 26/8/2019 | 17/6/2026 | wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex. | |
| Modificada | Crítica (9.8) | 2.9% | — | Wolfvision Cynap | 5/7/2019 | 17/6/2026 | WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access. | |
| Modificada | Crítica (9.8) | 9.2% | — | Wolfssl | 23/5/2019 | 17/6/2026 | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions… | |
| Modificada | Media (4.8) | 1.0% | — | Wolfcms Wolf CMS | 25/4/2019 | 17/6/2026 | WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | |
| Modificada | Media (4.8) | 1.0% | — | Wolfcms Wolf CMS | 25/4/2019 | 17/6/2026 | WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | |
| Modificada | Media (6.1) | 0.86% | — | Wolfcms Wolf CMS | 30/3/2019 | 17/6/2026 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded. | |
| Modificada | Crítica (9.8) | 2.6% | — | Wolfssl | 16/1/2019 | 17/6/2026 | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow. | |
| Modificada | Media (5.9) | 1.6% | — | Wolfssl | 3/1/2019 | 17/6/2026 | It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data. | |
| Modificada | Alta (7.5) | 1.3% | — | Lwolf Loading Docs | 12/9/2018 | 17/6/2026 | Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs. | |
| Modificada | Media (4.8) | 0.66% | — | Wolfcms Wolf CMS | 25/8/2018 | 17/6/2026 | WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. | |
| Modificada | Media (4.8) | 0.67% | — | Wolfcms Wolf CMS | 10/8/2018 | 17/6/2026 | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. | |
| Modificada | Crítica (9.8) | 1.6% | — | Wolfsight CMS | 12/7/2018 | 17/6/2026 | WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI. | |
| Modificada | Media (4.7) | 0.39% | — | Wolfssl | 15/6/2018 | 17/6/2026 | wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Werewolf Online Project Werewolf Online | 26/5/2018 | 17/6/2026 | The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. |