Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | 0.16% | — | Sonaar MP3 Audio Player FOR Music Radio PodcastAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2. | |
| Recibida | Media (5.3) | 0.26% | — | BouncycastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it, so a small input could dictate an arbitrary amount of work before anything could be… | |
| Recibida | Alta (8.2) | 0.16% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an implementation to release the cleartext of the fully authenticated chunks when streaming but requires… | |
| Recibida | Media (6.9) | 0.17% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the… | |
| Recibida | Alta (7.1) | 0.17% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a foreign ECCurve that merely shares BLS12-381's field characteristic. The… | |
| Recibida | Alta (8.7) | 0.25% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed leaf index but never established that the removed leaf had anything to do with the joiner.… | |
| Recibida | Alta (8.7) | 0.17% | — | BouncycastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index… | |
| Recibida | Alta (8.7) | 0.11% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2… | |
| Recibida | Alta (8.2) | 0.09% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3… | |
| Recibida | Alta (8.2) | 0.17% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and… | |
| Recibida | Crítica (9.2) | 0.19% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored… | |
| Recibida | Alta (8.2) | 0.25% | — | Bouncycastle LTSAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays with JNI's ReleaseByteArrayElements in mode 0, which commits the native copy back into the Java array. Those arrays are… | |
| Recibida | Media (5.9) | 0.11% | — | BouncycastleAI | 3/10/2026 | 5/10/2026 | In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its fixed-weight support sampler left its duplicate scan as soon as a collision was found… | |
| En análisis | Alta (7.1) | 0.33% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to… | |
| En análisis | Alta (8.2) | 0.24% | — | Bouncycastle BC CsharpAI | 2/10/2026 | 2/10/2026 | Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by… | |
| En análisis | Alta (8.2) | 0.22% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded… | |
| En análisis | Alta (7.1) | 0.19% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial… | |
| En análisis | Alta (8.7) | 0.32% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted… | |
| En análisis | Alta (8.2) | 0.31% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts… | |
| En análisis | Alta (7.1) | 0.33% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in… | |
| En análisis | Alta (8.7) | 0.17% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to have a forged X.509 attribute certificate accepted as valid, and so… | |
| En análisis | Alta (7.1) | 0.21% | — | Legion OF THE Bouncy Castle INC BC CsharpAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never… | |
| En análisis | Alta (8.2) | 0.28% | — | Bouncycastle Bouncy CastleAI | 2/10/2026 | 2/10/2026 | In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor,… | |
| En análisis | Media (5.3) | 0.44% | — | BouncycastleAI | 2/10/2026 | 2/10/2026 | In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The… | |
| En análisis | Alta (8.7) | 0.32% | — | Bouncycastle Bouncy CastleAI | 2/10/2026 | 2/10/2026 | In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate encoding rather than malformed input, and it must still decode, since the MLS interop test… |