Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.55% | — | WP EncryptionAI | 23/7/2026 | 24/7/2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Baja (1.9) | 0.06% | — | Steeltoe Configuration.encryptionAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the… | |
| Aplazada | Media (5.4) | 0.24% | — | WP EncryptionAI | 14/5/2026 | 17/6/2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' function in all versions up to, and including, 7.8.5.10. This makes it possible for… | |
| Pendiente de análisis | Media (5.7) | 0.10% | — | Amazon AWS Encryption SDK FOR PythonAI | 20/4/2026 | 17/6/2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple… | |
| Aplazada | Media (6) | 0.11% | — | Amazon S3 Encryption Client FOR GOAI | 17/12/2025 | 30/9/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade… | |
| Aplazada | Media (6) | 0.12% | — | Amazon S3 Encryption Client FOR JavaAI | 17/12/2025 | 17/6/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,… | |
| Aplazada | Media (6) | 0.11% | — | Amazon S3 Encryption Client FOR .netAI | 17/12/2025 | 17/6/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,… | |
| Analizada | Media (6.5) | 0.13% | — | Pcisig PCI Express Integrity AND Data Encryption | 9/12/2025 | 17/6/2026 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead to unintended data… | |
| Analizada | Media (6.5) | 0.21% | — | Pcisig PCI Express Integrity AND Data Encryption | 9/12/2025 | 17/6/2026 | A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered… | |
| Analizada | Media (5.1) | 0.14% | — | Pcisig PCI Express Integrity AND Data Encryption | 9/12/2025 | 17/6/2026 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical attackers on the… | |
| Analizada | Alta (7.3) | 0.10% | — | Dell Encryption | 9/12/2025 | 17/6/2026 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.6) | 0.09% | — | Dell Encryption | 9/12/2025 | 17/6/2026 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Media (4.6) | 0.19% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user. | |
| Analizada | Media (5.6) | 0.30% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell EncryptionDell Security Management Server | 30/7/2025 | 17/6/2026 | Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method. | |
| Analizada | Crítica (9.8) | 0.55% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | |
| Analizada | Alta (8.8) | 0.33% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.84% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Encryption | 3/6/2025 | 17/6/2026 | Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. | |
| Aplazada | Media (4.6) | 0.26% | — | Simple Python EncryptionAI | 8/5/2025 | 17/6/2026 | Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versions prior to commit 6ce60b1, an attacker may be able to decrypt the data using brute force attacks and because of this the whole application can be impacted. This issue has been patched in commit… |