Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.32% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:… | |
| Analizada | Alta (8.3) | 0.59% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,… | |
| Analizada | Alta (8.2) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce… | |
| Analizada | Alta (8.7) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).… | |
| Modificada | Baja (3.5) | 0.94% | — | Commerce Balanced Payments Project Commerce Balanced Payments | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments PROZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP… | |
| Modificada | Media (5.8) | 5.7% | — | Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+1 | 4/11/2012 | 16/6/2026 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… |