Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Sequoia OpenpgpAI | 16/9/2026 | 23/9/2026 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can… | |
| Analizada | Media (5.3) | 0.29% | — | Sequoia-pgp Sequoia-openpgp | 28/7/2025 | 17/6/2026 | The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. | |
| Analizada | Alta (7.5) | 0.38% | — | Sequoia-pgp Sequoia-openpgp | 27/7/2025 | 17/6/2026 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. | |
| Aplazada | Alta (8.7) | 0.65% | — | Openpgp.jsAI | 19/5/2025 | 17/6/2026 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data… | |
| Analizada | Media (4.6) | 0.25% | — | Arnesonium Openpgp Form Encryption | 13/7/2024 | 17/6/2026 | The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.3) | 0.35% | — | Openpgpjs | 29/8/2023 | 17/6/2026 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typically contain a "Hash: ..." header declaring the hash algorithm used to compute the… | |
| Modificada | Alta (8.8) | 0.67% | — | Yubico Ykneo-openpgp | 30/3/2022 | 17/6/2026 | Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated. | |
| Modificada | Media (5.9) | 1.5% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key. | |
| Modificada | Alta (7.5) | 1.6% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. | |
| Modificada | Alta (7.5) | 2.0% | — | Openpgpjs | 22/8/2019 | 17/6/2026 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature. | |
| Modificada | Alta (7.5) | 3.9% | — | Openpgpjs | 25/7/2017 | 17/6/2026 | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message. | |
| Analizada | Media (5) | 80% | — | Juniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+8 | 18/8/2004 | 16/6/2026 | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP. | |
| Modificada | Media (4.6) | 0.37% | — | Openpgp | 27/6/2001 | 16/6/2026 | The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key. |