Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | — | — | OpenscAI | 30/9/2026 | 1/10/2026 | A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called… | |
| Aplazada | Baja (1.3) | 0.30% | — | OpenscAI | 1/6/2026 | 22/7/2026 | A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high.… | |
| Analizada | Baja (1) | 0.15% | — | Opensc Project Opensc | 29/5/2026 | 21/7/2026 | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry beginning with '='… | |
| Analizada | Baja (1) | 0.25% | — | Opensc Project Opensc | 29/5/2026 | 21/7/2026 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes… | |
| Pendiente de análisis | Media (5.7) | 0.18% | — | LibopenscAI | 23/4/2026 | 30/6/2026 | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs | |
| Analizada | Media (6.8) | 0.16% | — | Opensc Project Opensc | 30/3/2026 | 17/6/2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system… | |
| Analizada | Media (6.8) | 0.28% | — | Opensc Project Opensc | 30/3/2026 | 17/6/2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claims tag=0 and length=10… | |
| Analizada | Media (6.8) | 0.25% | — | Opensc Project Opensc | 30/3/2026 | 17/6/2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields() allocates a zero-length buffer and then… | |
| Analizada | Media (6.8) | 0.13% | — | Opensc Project Opensc | 30/3/2026 | 17/6/2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system… | |
| Aplazada | Media (6.7) | 0.23% | — | Opensc PAM Pkcs11AI | 16/1/2026 | 17/6/2026 | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass. | |
| Aplazada | Alta (7.2) | 0.90% | — | Mitel Openscape Accounting ManagementAI | 23/6/2025 | 17/6/2026 | Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to upload arbitrary files and execute unauthorized commands. | |
| Aplazada | Alta (7.5) | 0.58% | — | Mitel Openscape XpressionsAI | 23/6/2025 | 17/6/2026 | A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive… | |
| Aplazada | Alta (7.3) | 1.2% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could… | |
| Aplazada | Alta (8.8) | 0.59% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute… | |
| Modificada | Baja (2.9) | 0.32% | — | Opensc Project OpenscRedhat Enterprise Linux | 10/9/2024 | 30/6/2026 | A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution. | |
| Modificada | Baja (3.9) | 0.32% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. | |
| Modificada | Media (4.3) | 0.33% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly… | |
| Modificada | Baja (3.9) | 0.31% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized. | |
| Modificada | Baja (3.9) | 0.33% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with… | |
| Modificada | Baja (3.9) | 0.36% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its… | |
| Modificada | Baja (3.9) | 0.36% | — | Redhat Enterprise LinuxOpensc Project Opensc | 3/9/2024 | 30/6/2026 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). | |
| Analizada | Alta (8.8) | 0.45% | — | Mitel 6940w FirmwareMitel 6930w FirmwareMitel 6920w FirmwareMitel 6970 Firmware+10 | 8/4/2024 | 17/6/2026 | In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password). | |
| Modificada | Baja (3.4) | 0.42% | — | Opensc Project OpenscFedoraproject FedoraRedhat Enterprise Linux | 12/2/2024 | 17/6/2026 | The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present… | |
| Analizada | Media (4.3) | 0.45% | — | Unify Openscape Voice Trace Manager | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface. | |
| Analizada | Alta (8.8) | 1.2% | — | Unify Openscape Voice Trace Manager | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp. |