Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.56%—Nasa CryptolibAI17/9/202618/9/2026
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Pendiente de análisisMedia (5.9)0.66%—Latchset JwcryptoAI16/9/202616/9/2026
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply a JWK with a large key_ops array to an application that passes…
AplazadaCrítica (10)0.50%—Cryptopayment GatewayAI13/9/202614/9/2026
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored…
AplazadaMedia (6.9)0.31%—Matrix-sdk-cryptoAI11/9/202630/9/2026
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the…
AplazadaMedia (5.9)0.33%—Mirage-crypto-ecAI9/9/20269/9/2026
An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.
AplazadaMedia (4.3)0.36%—Mirage-crypto-ecAI9/9/202614/9/2026
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
AplazadaMedia (4.3)0.23%—Mirage-crypto-pkAI9/9/20269/9/2026
An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.
AplazadaMedia (6.2)0.15%—Mirage-crypto-ecAI9/9/20269/9/2026
An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.
AplazadaMedia (6.2)0.11%—Mirage-cryptoAI9/9/20269/9/2026
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the…
Pendiente de análisisMedia (5.9)0.13%—Latchset JwcryptoAI3/9/20268/9/2026
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid)…
AnalizadaAlta (7.5)0.43%—Golang Crypto2/9/20264/9/2026
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet…
AnalizadaAlta (7.5)0.50%—Golang Crypto2/9/20264/9/2026
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of…
Pendiente de análisisMedia (5.9)0.41%—Latchset JwcryptoAI28/8/202631/8/2026
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for…
AplazadaMedia (5.7)0.17%—Kriptok Crypto AND Information Technologies Industry Trade INC CryptosimAI18/8/202626/8/2026
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.
AplazadaCrítica (9.1)0.44%—JsbnAIJuneandgreen Sm-cryptoAI13/8/202618/9/2026
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random()…
AplazadaMedia (5.9)0.09%—Oberon Microsystem AG Oberon PSA Crypto LibraryAI13/8/202626/8/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
AplazadaMedia (5.9)0.09%—Oberon Microsystem AG OcryptoAI13/8/202626/8/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
AplazadaCrítica (9.1)0.20%—Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaAlta (8.4)0.14%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high…
AplazadaAlta (7.5)0.49%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
AplazadaCrítica (9.8)0.78%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
AplazadaMedia (4.6)0.24%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
AplazadaAlta (7.2)0.67%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high…
AplazadaAlta (7.5)0.19%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaCrítica (9.8)0.65%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.