Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 28 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Nasa CryptolibAI | 17/9/2026 | 18/9/2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. | |
| Analizada | Alta (7.5) | 0.53% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, CryptoLib’s KMC crypto service integration is vulnerable to a… | |
| Analizada | Media (5.7) | 0.24% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the convert_hexstring_to_byte_array() function in the MariaDB SA… | |
| Analizada | Alta (8.2) | 0.61% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the libcurl write_callback function in the KMC crypto service… | |
| Analizada | Media (6.3) | 0.55% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, when the KMC server returns a non-200 HTTP status code,… | |
| Analizada | Media (6.3) | 0.49% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography_encrypt() function allocates multiple buffers… | |
| Analizada | Alta (8.2) | 0.58% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, there is an out-of-bounds heap read vulnerability in… | |
| Analizada | Alta (8.2) | 0.58% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, an out-of-bounds heap read vulnerability in… | |
| Analizada | Media (4.9) | 0.35% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode, padding-stripping dereferences… | |
| Analizada | Alta (8.2) | 0.46% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_AOS_ProcessSecurity function reads memory without… | |
| Analizada | Alta (7.3) | 0.29% | — | Nasa Cryptolib | 10/1/2026 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_Config_Add_Gvcid_Managed_Parameters function only… | |
| Aplazada | Alta (7.5) | 0.43% | — | SAP CommoncryptolibAI | 11/11/2025 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity. | |
| Modificada | Alta (8.8) | 0.52% | — | Nasa Cryptolib | 30/10/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to 1.4.2, there is a missing bounds check in Crypto_Key_update()… | |
| Analizada | Alta (7.8) | 0.91% | — | Nasa Cryptolib | 23/9/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.2, there is a command Injection vulnerability in… | |
| Analizada | Alta (8.6) | 0.39% | — | Nasa Cryptolib | 11/8/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow vulnerability exists in NASA CryptoLib version 1.4.0 and prior in… | |
| Analizada | Media (4.2) | 0.35% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. | |
| Analizada | Crítica (9.9) | 0.60% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle. | |
| Analizada | Crítica (9.9) | 0.50% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS). | |
| Analizada | Alta (8.8) | 0.53% | — | Nasa Cryptolib | 27/4/2025 | 17/6/2026 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. | |
| Analizada | Crítica (9.3) | 0.66% | — | Nasa Cryptolib | 1/4/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In 1.3.3 and earlier, a heap buffer overflow vulnerability persists in the… | |
| Analizada | Crítica (9.1) | 2.6% | — | Nasa Cryptolib | 25/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in the… | |
| Analizada | Alta (8.9) | 0.72% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability was identified in the `Crypto_TC_Prep_AAD`… | |
| Analizada | Alta (8.9) | 1.1% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer underflow in the… | |
| Analizada | Alta (8.9) | 0.74% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability was identified in the… | |
| Analizada | Media (5.5) | 0.49% | — | Nasa Cryptolib | 17/3/2025 | 17/6/2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory leak vulnerability was identified in the… |