Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.09%—Oberon Microsystem AG Oberon PSA Crypto LibraryAI13/8/202626/8/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
AnalizadaCrítica (9.1)0.28%—ARM Mbed TLSARM Tf-psa-crypto1/4/202617/6/2026
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is…
AnalizadaMedia (5.1)0.27%—ARM Mbed TLSARM Tf-psa-crypto1/4/202617/6/2026
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
AnalizadaMedia (6.7)0.15%—ARM Mbed TLSTrustedfirmware Tf-psa-crypto1/4/202617/6/2026
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).
AnalizadaAlta (7.7)0.18%—ARM Mbed TLSTrustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto1/4/202617/6/2026
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
AnalizadaCrítica (9.8)0.60%—Trustedfirmware Mbed TLSTrustedfirmware Tf-psa-crypto1/4/202617/6/2026
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
AplazadaBaja (2.3)0.29%—Silabs PSA CryptoAISilabs SE ManagerAI20/2/202617/6/2026
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.
AplazadaBaja (2.3)0.18%—Oberon Microsystems AG Oberon PSA Crypto LibraryAI29/8/202517/6/2026
Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG’s Oberon PSA Crypto library in all versions up to 1.5.1, results in deterministic RSA and thus in a loss of confidentiality for guessable messages, recognition of repeated messages, and loss of…
AplazadaMedia (5.9)0.09%—Oberon Microsystem Oberon PSA CryptoAI29/8/202517/6/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 1.5.1 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.