Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.3)0.19%—Openzeppelin WizardAIOpenzeppelin Wizard CairoAIOpenzeppelin Wizard StellarAIOpenzeppelin Wizard StylusAI14/9/202630/9/2026
OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints…
Pendiente de análisisAlta (7.3)0.20%—OpenzfsAI26/8/202628/8/2026
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg…
AplazadaMedia (6.6)0.52%—Openzeppelin Confidential ContractsAIZama FhevmAI13/8/202618/9/2026
OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap and onTransferReceived functions in…
AplazadaAlta (8.8)0.64%—Openzeppelin Contracts WizardAIHardhatAI6/8/202614/9/2026
OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string…
AplazadaAlta (8.7)0.34%—OpenzitiAI30/6/202614/7/2026
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in…
AplazadaMedia (5.1)0.29%—Openz ERPAI30/1/202617/6/2026
OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.
AplazadaMedia (6.9)0.35%—Openzeppelin ContractsAI17/7/202517/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to version 5.4.0, the `lastIndexOf(bytes,byte,uint256)` function of the `Bytes.sol` library may access uninitialized memory when the following two conditions hold: 1) the provided buffer length is empty (i.e.…
AnalizadaAlta (8.6)0.40%—Openziti3/3/202517/6/2026
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller and performs a server-side request, resulting in a…
AnalizadaMedia (6.1)0.28%—Openziti3/3/202517/6/2026
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This endpoint accepts an HTTP POST to upload a file which is then stored on the node and is available via URL. This can lead to a…
AnalizadaMedia (6.5)0.48%—Openzeppelin Contracts31/8/202417/6/2026
Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving the contract without an owner. It introduces a security risk where an unintended party (pending…
AnalizadaAlta (7.4)0.76%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable21/3/202417/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed…
ModificadaAlta (7.5)0.54%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable9/12/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4`, all subcalls are executed twice.…
ModificadaAlta (7.5)1.2%—Openzfs24/11/202317/6/2026
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related…
ModificadaMedia (5.3)0.74%—Openzeppelin ContractsOpenzeppelin Contracts-upgradable10/8/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20…
ModificadaMedia (5.9)0.37%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to construct merkle trees that allow forging a…
ModificadaMedia (5.3)0.60%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable7/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in…
ModificadaMedia (5.3)0.81%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable17/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert…
ModificadaAlta (8.8)0.58%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if…
ModificadaMedia (6.5)0.71%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable3/3/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by…
ModificadaMedia (5.3)0.22%—Openzeppelin Contracts3/2/202317/6/2026
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using `is_valid_eth_signature` from the account…
ModificadaMedia (5.6)0.53%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable4/11/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an…
ModificadaMedia (6.5)0.42%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable15/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditional 65 byte signature format. This is only an issue for the…
ModificadaMedia (5.3)0.58%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned accounts (EOAs) as cross chain calls, even though they are not started on L1.…
ModificadaMedia (5.3)0.78%—Openzeppelin ContractsOpenzeppelin Contracts UpgradeableOpenzeppelin-ethOpenzeppelin-solidity1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are…
ModificadaAlta (7.5)0.77%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable1/8/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as a percentage of the voting token's total supply. In affected instances, when a proposal is passed to…