Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.4)0.20%—Sequoia OpenpgpAI16/9/202623/9/2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can…
AnalizadaMedia (5.3)0.29%—Sequoia-pgp Sequoia-openpgp28/7/202517/6/2026
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
AnalizadaAlta (7.5)0.38%—Sequoia-pgp Sequoia-openpgp27/7/202517/6/2026
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
AplazadaAlta (8.7)0.65%—Openpgp.jsAI19/5/202517/6/2026
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data…
AnalizadaMedia (4.6)0.25%—Arnesonium Openpgp Form Encryption13/7/202417/6/2026
The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (4.3)0.35%—Openpgpjs29/8/202317/6/2026
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typically contain a "Hash: ..." header declaring the hash algorithm used to compute the…
ModificadaAlta (8.8)0.67%—Yubico Ykneo-openpgp30/3/202217/6/2026
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
ModificadaMedia (5.9)1.5%—Openpgpjs22/8/201917/6/2026
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
ModificadaAlta (7.5)1.6%—Openpgpjs22/8/201917/6/2026
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
ModificadaAlta (7.5)2.0%—Openpgpjs22/8/201917/6/2026
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
ModificadaAlta (7.5)3.9%—Openpgpjs25/7/201717/6/2026
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.
AnalizadaMedia (5)80%—Juniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+818/8/200416/6/2026
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
ModificadaMedia (4.6)0.37%—Openpgp27/6/200116/6/2026
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.