Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.4)0.55%—WP EncryptionAI23/7/202624/7/2026
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level…
AplazadaBaja (1.9)0.06%—Steeltoe Configuration.encryptionAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the…
AplazadaMedia (5.4)0.24%—WP EncryptionAI14/5/202617/6/2026
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' function in all versions up to, and including, 7.8.5.10. This makes it possible for…
Pendiente de análisisMedia (5.7)0.10%—Amazon AWS Encryption SDK FOR PythonAI20/4/202617/6/2026
Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple…
AplazadaMedia (6)0.11%—Amazon S3 Encryption Client FOR GOAI17/12/202530/9/2026
Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade…
AplazadaMedia (6)0.12%—Amazon S3 Encryption Client FOR JavaAI17/12/202517/6/2026
Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,…
AplazadaMedia (6)0.11%—Amazon S3 Encryption Client FOR .netAI17/12/202517/6/2026
Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,…
AnalizadaMedia (6.5)0.13%—Pcisig PCI Express Integrity AND Data Encryption9/12/202517/6/2026
An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead to unintended data…
AnalizadaMedia (6.5)0.21%—Pcisig PCI Express Integrity AND Data Encryption9/12/202517/6/2026
A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered…
AnalizadaMedia (5.1)0.14%—Pcisig PCI Express Integrity AND Data Encryption9/12/202517/6/2026
An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical attackers on the…
AnalizadaAlta (7.3)0.10%—Dell Encryption9/12/202517/6/2026
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (6.6)0.09%—Dell Encryption9/12/202517/6/2026
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
AnalizadaMedia (4.6)0.19%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.
AnalizadaMedia (5.6)0.30%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
AnalizadaAlta (7.8)0.14%—Dell EncryptionDell Security Management Server30/7/202517/6/2026
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.
AnalizadaAlta (7.8)0.13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
AnalizadaCrítica (9.8)1.1%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
AnalizadaCrítica (9.8)0.55%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
AnalizadaAlta (8.8)0.33%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaAlta (8.8)0.84%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaCrítica (9.8)13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
AnalizadaCrítica (9.8)13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
AnalizadaAlta (7.8)0.13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaAlta (7.8)0.13%—Dell Encryption3/6/202517/6/2026
Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.
AplazadaMedia (4.6)0.26%—Simple Python EncryptionAI8/5/202517/6/2026
Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versions prior to commit 6ce60b1, an attacker may be able to decrypt the data using brute force attacks and because of this the whole application can be impacted. This issue has been patched in commit…