Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.27% | — | IXO BlockchainAI | 24/9/2026 | 30/9/2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included… | |
| Aplazada | Media (4.3) | 0.40% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can legally contain an empty… | |
| Aplazada | Alta (7.5) | 0.76% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a signature… | |
| Analizada | Baja (1.1) | 0.24% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's complexity is rated as high. The… | |
| Analizada | Baja (1.3) | 0.23% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit… | |
| Analizada | Baja (2.9) | 0.90% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out remotely. The attack is considered to… | |
| Aplazada | Media (5.4) | 0.30% | — | BSV Blockchain Typescript SDKAI | 18/2/2026 | 17/6/2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK… | |
| Aplazada | Alta (7.5) | 0.59% | — | TON BlockchainAITON Virtual MachineAI | 13/2/2026 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a malicious… | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (4.4) | 0.15% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.15% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (4.4) | 0.16% | — | Samsung Blockchain Keystore | 4/2/2025 | 17/6/2026 | Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory. | |
| Analizada | Media (4.4) | 0.15% | — | Samsung Blockchain Keystore | 4/2/2025 | 17/6/2026 | Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (4.4) | 0.10% | — | Samsung Blockchain Keystore | 6/11/2024 | 17/6/2026 | Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability. | |
| Modificada | Media (5.3) | 0.42% | — | Ethereum Blockchain | 11/9/2023 | 17/6/2026 | An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold. | |
| Modificada | Alta (7.8) | 0.18% | — | Samsung Blockchain Keystore | 6/9/2023 | 17/6/2026 | Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.50% | — | Nesote Inout Blockchain Easypayments | 15/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an unknown function of the file /index.php/payment/getcoinaddress of the component POST Parameter Handler. The manipulation of the argument coinid leads to sql injection. It is possible to launch the… | |
| Modificada | Crítica (9.8) | 0.50% | — | Nesote Inout Blockchain Fiatexchanger | 11/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Nesote Inout Blockchain FiatExchanger 3.0. This affects an unknown part of the file /index.php/coins/update_marketboxslider of the component POST Parameter Handler. The manipulation of the argument marketcurrency leads to sql injection. It is possible to… | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. |