Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | Perl Crypt DSAAI | 5/7/2026 | 6/7/2026 | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are… | |
| Aplazada | Crítica (9.1) | 0.29% | — | Crypt DSAAI | 15/6/2026 | 17/6/2026 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it,… | |
| Aplazada | Media (6.5) | 0.36% | — | Perl Crypt DSAAI | 15/5/2026 | 17/6/2026 | Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified. | |
| Aplazada | Alta (7.3) | 0.41% | — | Crypt DSAAI | 15/5/2026 | 17/6/2026 | Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. | |
| Modificada | Media (5.8) | 2.0% | — | Adam Kennedy Crypt-dsa | 10/10/2011 | 16/6/2026 | The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack. |